proper self-service login supporting plaintext, crypt and MD5 passwords
[freeside.git] / httemplate / docs / install.html
1 <head>
2   <title>Installation</title>
3 </head>
4 <body>
5 <h1>Installation</h1>
6 <i>Note: Install Freeside on a firewalled, private server, not a public (web, RADIUS, etc.) server.</i><br><br>
7 Before installing, you need:
8 <ul>
9   <li><a href="http://www.perl.com/">Perl</a>
10   <li><a href="http://www.apache.org">Apache</a> (<a href="http://www.modssl.org/">mod_ssl</a> or <a href="http://www.apache-ssl.org">Apache-SSL</a> highly recommended)
11   <li><a href="http://perl.apache.org/">mod_perl</a> (if compiling your own mod_perl, make sure you set the <a href="http://perl.apache.org/guide/install.html#EVERYTHING">EVERYTHING</a>=1 compile-time option)
12   <li><a href="http://www.openssh.com/">SSH</a> (<a href="http://www.openssh.com//">OpenSSH</a> is recommended.  SSH Communications Security <a href="http://www.ssh.com/products/ssh/download.cfm">commercial SSH version 3</a> has been reported incompatible with Freeside.)
13   <li><a href="http://rsync.samba.org/">rsync</a>
14   <li>A <b>transactional</b> database engine <a href="http://search.cpan.org/search?mode=module&query=DBD%3A%3A">supported</a> by Perl's <a href="http://dbi.perl.org">DBI</a>.
15     <ul>
16       <li><a href="http://www.postgresql.org/">PostgreSQL</a> is recommended (v7or later).
17       <li><a href="http://www.mysql.com/">MySQL</a> <b>MINIMUM VERSION 4.1</b> is untested but may work.   Versions before 4.1 do not support standard SQL subqueries and are <b>NOT SUPPORTED</b>.  If you are a developer who wishes to contribute MySQL 3.x/4.0 support, see <a href="http://pouncequick.420.am/rt/Ticket/Display.html?id=438">ticket #438</a> in the bug-tracking system and ask on the -devel mailing list.
18 <!--       <li>MySQL has been reported to work. -->
19          <b>MySQL's default <a href="http://www.mysql.com/doc/M/y/MyISAM.html">MyISAM</a> and <a href="http://www.mysql.com/doc/I/S/ISAM.html">ISAM</a> table types are not supported</b>.  If you want to use MySQL, you <b>must</b> use one of the new <a href="http://www.mysql.com/doc/T/a/Table_types.html">transaction-safe table types</a> such as <a href="http://www.mysql.com/doc/B/D/BDB.html">BDB</a> or <a href="http://www.mysql.com/doc/I/n/InnoDB.html">InnoDB</a>, and set it as the default table type using the <code>--default-table-type=BDB</code> or <code>--default-table-type=InnoDB</code> <a href="http://www.mysql.com/documentation/mysql/bychapter/manual_MySQL_Database_Administration.html#Command-line_options">mysqld command-line option</a> or by setting <code>default-table-type=BDB</code> or <code>default-table-type=InnoDB</code> in the <a href="http://www.mysql.com/documentation/mysql/bychapter/manual_MySQL_Database_Administration.html#Option_files">my.cnf option file</a>.
20     </ul>
21   <li>Perl modules (<a href="http://search.cpan.org/~andk/CPAN/lib/CPAN.pm">CPAN</a> will query, download and build perl modules automatically)
22     <ul>
23 <!--      <li><a href="http://search.cpan.org/search?dist=Array-PrintCols">Array-PrintCols</a>
24       <li><a href="http://search.cpan.org/search?dist=Term-Query">Term-Query</a> (make test broken; install manually) -->
25       <li><a href="http://search.cpan.org/search?dist=MIME-Base64">MIME-Base64</a>
26       <li><a href="http://search.cpan.org/search?dist=Digest-MD5">Digest-MD5</a>
27 <!--      <li><a href="http://search.cpan.org/search?dist=MD5">MD5</a> -->
28       <li><a href="http://search.cpan.org/search?dist=URI">URI</a>
29       <li><a href="http://search.cpan.org/search?dist=HTML-Tagset">HTML-Tagset</a>
30       <li><a href="http://search.cpan.org/search?dist=HTML-Parser">HTML-Parser</a>
31       <li><a href="http://search.cpan.org/search?dist=libnet">libnet</a>
32       <li><a href="http://search.cpan.org/search?dist=Locale-Codes">Locale-Codes</a>
33       <li><a href="http://search.cpan.org/search?dist=Net-Whois">Net-Whois</a>
34       <li><a href="http://search.cpan.org/search?dist=libwww-perl">libwww-perl</a>
35       <li><a href="http://search.cpan.org/search?dist=Business-CreditCard">Business-CreditCard</a>
36 <!--      <li><a href="http://search.cpan.org/search?dist=Data-ShowTable">Data-ShowTable</a> -->
37       <li><a href="http://search.cpan.org/search?dist=MailTools">MailTools</a>
38       <li><a href="http://search.cpan.org/search?dist=TimeDate">TimeDate</a>
39       <li><a href="http://search.cpan.org/search?dist=DateManip">DateManip</a>
40       <li><a href="http://search.cpan.org/search?dist=File-CounterFile">File-CounterFile</a>
41       <li><a href="http://search.cpan.org/search?dist=FreezeThaw">FreezeThaw</a>
42       <li><a href="http://search.cpan.org/search?dist=String-Approx">String-Approx</a>
43       <li><a href="http://search.cpan.org/search?dist=Text-Template">Text-Template</a>
44       <li><a href="http://search.cpan.org/search?dist=DBI">DBI</a>
45       <li><a href="http://search.cpan.org/search?mode=module&query=DBD">DBD for your database engine</a> (<a href="http://search.cpan.org/search?dist=DBD-Pg">DBD::Pg</a> for PostgreSQL, <a href="http://search.cpan.org/search?dist=DBD-mysql">DBD::mysql</a> for MySQL)
46       <li><a href="http://search.cpan.org/search?dist=DBIx-DataSource">DBIx-DataSource</a>
47       <li><a href="http://search.cpan.org/search?dist=DBIx-DBSchema">DBIx-DBSchema</a>
48       <li><a href="http://search.cpan.org/search?dist=Net-SSH">Net-SSH</a>
49       <li><a href="http://search.cpan.org/search?dist=String-ShellQuote">String-ShellQuote</a>
50       <li><a href="http://search.cpan.org/search?dist=Net-SCP">Net-SCP</a>
51       <li><a href="http://www.apache-asp.org/">Apache::ASP</a> or <a href="http://www.masonhq.com/">HTML::Mason</a>
52       <li><a href="http://search.cpan.org/search?dist=Tie-IxHash">Tie-IxHash</a>
53       <li><a href="http://search.cpan.org/search?dist=Time-Duration">Time-Duration</a>
54       <li><a href="http://search.cpan.org/search?dist=HTML-Widgets-SelectLayers">HTML-Widgets-SelectLayers</a>
55       <li><a href="http://search.cpan.org/search?dist=Storable">Storable</a>
56 <!-- MyAccounts, maybe only for dev     <li><a href="http://search.cpan.org/search?dist=Cache-Cache">Cache::Cache</a> -->
57       <li><a href="http://search.cpan.org/search?dist=NetAddr-IP">NetAddr-IP</a>
58       <li><a href="http://search.cpan.org/search?dist=Chart">Chart</a>
59       <li><a href="http://search.cpan.org/search?dist=Crypt-PasswdMD5">Crypt::PasswdMD5</a>
60       <li><a href="http://search.cpan.org/search?dist=ApacheDBI">Apache::DBI</a> <i>(optional but recommended for better webinterface performance)</i>
61     </ul>
62 </ul>
63 Install the Freeside distribution:
64 <ul>
65   <li>Add the user and group `freeside' to your system.
66   <li>Allow the freeside user full access to the freeside database.
67     <ul>
68       <li> with <a href="http://www.postgresql.org/users-lounge/docs/7.1/postgres/user-manag.html#DATABASE-USERS">PostgreSQL</a>:
69         <pre>
70 $ su postgres (pgsql on some distributions)
71 $ createuser -P freeside
72 Enter password for user "freeside": 
73 Enter it again: 
74 Shall the new user be allowed to create databases? (y/n) y
75 Shall the new user be allowed to create more new users? (y/n) n
76 CREATE USER</pre>
77       <li> with <a href="http://www.mysql.com/documentation/mysql/bychapter/manual_MySQL_Database_Administration.html#User_Account_Management">MySQL</a>:
78         <pre>
79 $ mysqladmin -u root password '<i>set_a_root_database_password</i>'
80 $ mysql -u root -p
81 mysql> GRANT SELECT,INSERT,UPDATE,DELETE,INDEX,ALTER,CREATE,DROP on freeside.* TO freeside@localhost IDENTIFIED BY '<i>set_a_freeside_database_password</i>';</pre>
82     </ul>
83 <!--  <li>Unpack the tarball: <pre>gunzip -c fs-x.y.z.tar.gz | tar xvf -</pre>-->
84   <li>Edit the top-level Makefile:
85     <ul>
86       <li>Set <tt>DATASOURCE</tt> to your <a href="http://search.cpan.org/doc/TIMB/DBI-1.28/DBI.pm">DBI data source</a>, for example, <tt>DBI:Pg:dbname=freeside</tt> for PostgresSQL or <tt>DBI:mysql:freeside</tt> for MySQL.  See the <a href="http://search.cpan.org/doc/TIMB/DBI-1.28/DBI.pm">DBI manpage</a> and the <a href="http://search.cpan.org/search?mode=module&query=DBD%3A%3A">manpage for your DBD</a> for the exact syntax of your DBI data source.
87       <li>Set <tt>DB_PASSWORD</tt> to the freeside database user's password.
88     </ul>
89   <li>Add the freeside database to your database engine:
90     <pre>
91 $ su
92 # make create-database</pre>
93     (or manually, with Postgres:)
94     <pre>
95 $ su freeside
96 $ createdb freeside</pre>
97     (with MySQL:)
98     <pre>
99 $ mysqladmin -u freeside -p create freeside </pre>
100   <li>Build and install the Perl modules:
101     <pre>
102 $ make perl-modules
103 $ su
104 # make install-perl-modules</pre>
105     <li>Create the necessary configuration files:<pre>
106 $ su
107 # make create-config
108 </pre>
109     <li>Run a <b>separate</b> iteration of Apache[-SSL] with mod_perl enabled <b>as the freeside user</b>.
110 </ul>
111 <table>
112   <tr>
113     <th>Apache::ASP</th><th>Mason</th>
114   </tr>
115   <tr>
116     <td><ul>
117       <li>Run <tt>make aspdocs</tt>
118       <li>Copy <tt>aspdocs/</tt> to your web server's document space:
119 <font size="-1"><pre>
120 cp&nbsp;aspdocs&nbsp;/usr/local/apache/htdocs/freeside-asp
121 </pre></font>
122       <li>Create a <a href="http://www.apache-asp.org/config.html#Global">Global</a> directory, such as <tt>/usr/local/etc/freeside/asp-global/</tt>:
123 <font size="-1"><pre>
124 mkdir&nbsp;/usr/local/etc/freeside/asp-global/
125 chown&nbsp;freeside&nbsp;/usr/local/etc/freeside/asp-global/
126 </pre></font>
127       <li>Copy <tt>htetc/global.asa</tt> to the Global directory:
128 <font size="-1"><pre>
129 cp&nbsp;htetc/global.asa&nbsp;/usr/local/etc/freeside/asp-global/global.asa
130 </pre></font>
131       <li>Configure Apache for the Global directory and to execute .cgi files using Apache::ASP.  For example:
132 <font size="-1"><pre>
133 PerlModule Apache::ASP
134 &lt;Directory&nbsp;/usr/local/apache/htdocs/freeside-asp&gt;
135 &lt;Files ~ (\.cgi|\.html)&gt;
136 SetHandler perl-script
137 PerlHandler Apache::ASP
138 &lt;/Files&gt;
139 &lt;Perl&gt;
140 $MLDBM::RemoveTaint = 1;
141 &lt;/Perl&gt;
142 PerlSetVar&nbsp;Global&nbsp;/usr/local/etc/freeside/asp-global/
143 PerlSetVar&nbsp;Debug&nbsp;2
144 PerlSetVar&nbsp;RequestBinaryRead&nbsp;Off
145 &lt;/Directory&gt;
146 </pre></font>
147     </ul></td>
148     <td><ul>
149       <li>Run <tt>make masondocs</tt>
150       <li>Copy <tt>masondocs/</tt> to your web server's document space. (For example: <tt>/usr/local/apache/htdocs/freeside-mason</tt>)
151       <li>Copy <tt>htetc/handler.pl</tt> to <tt>/usr/local/etc/freeside</tt>
152       <li>Edit <tt>handler.pl</tt> and:
153       <ul>
154         <li> set an appropriate <tt>comp_root</tt>, such as <tt>/usr/local/apache/htdocs/freeside-mason</tt>
155         <li> set an appropriate <tt>data_dir</tt>, such as <tt>/usr/local/etc/freeside/masondata</tt>
156       </ul>
157
158       <li>Configure Apache to use the <tt>handler.pl</tt> file and to execute .cgi files using HTML::Mason.  For example:
159 <font size="-1"><pre>
160 PerlModule HTML::Mason
161 &lt;Directory&nbsp;/usr/local/apache/htdocs/freeside-mason&gt;
162 &lt;Files ~ (\.cgi|.html)&gt;
163 SetHandler perl-script
164 PerlHandler HTML::Mason
165 &lt;/Files&gt;
166 &lt;Perl&gt;
167 require&nbsp;"/usr/local/etc/freeside/handler.pl";
168 &lt;/Perl&gt;
169 &lt;/Directory&gt;
170 </pre></font>
171     </ul></td>
172   </tr>
173 </table>
174 <ul>
175 <li>Restrict access to this web interface - see the <a href="http://httpd.apache.org/docs/misc/FAQ.html#user-authentication">Apache documentation on user authentication</a>.    For example, to configure user authentication with <a href="http://httpd.apache.org/docs/mod/mod_auth.html">mod_auth</a> (flat files):
176 <pre>
177 &lt;Directory /usr/local/apache/htdocs/freeside-asp&gt;
178 AuthName Freeside
179 AuthType Basic
180 AuthUserFile /usr/local/etc/freeside/htpasswd
181 require valid-user
182 &lt;/Directory&gt;
183 </pre>
184   <li>Create one or more Freeside users (your internal sales/tech folks, not customer accounts).  These users are setup using using Apache authentication, not UNIX user accounts.  For example, using <a href="http://httpd.apache.org/docs/mod/mod_auth.html">mod_auth</a> (flat files):
185     <ul>
186       <li>First user:<font size="-1">
187 <pre>$ su
188 $ <a href="man/bin/freeside-adduser.html">freeside-adduser</a> -c -h /usr/local/etc/freeside/htpasswd <i>username</i></pre></font>
189       <li>Additional users:<font size="-1">
190 <pre>$ su
191 $ <a href="man/bin/freeside-adduser.html">freeside-adduser</a> -h /usr/local/etc/freeside/htpasswd <i>username</i></pre></font>
192     </ul>
193   <i>(using other auth types, add each user to your <a href="http://httpd.apache.org/docs/misc/FAQ.html#user-authentication">Apache authentication</a> and then run: <tt>freeside-adduser <b>username</b></tt></i>
194   <li>As the freeside UNIX user, run <tt>freeside-setup <b>username</b></tt> to create the database tables, passing the username of a Freeside user you created above:
195 <pre>
196 $ su freeside
197 $ freeside-setup <b>username</b>
198 </pre>
199   Alternately, use the -s option to enable shipping addresses: <tt>freeside-setup -s <b>username</b></tt>
200   <li>As the freeside UNIX user, run <tt>bin/populate-msgcat <b>username</b></tt> (in the untar'ed freeside directory) to populate the message catalog, passing the username of a Freeside user you created above:
201 <pre>
202 $ su freeside
203 $ cd <b>/path/to/freeside/</b>
204 $ bin/populate-msgcat <b>username</b>
205 </pre>
206   <li><tt>freeside-queued</tt> was installed with the Perl modules.  Start it now and ensure that is run upon system startup (Do this manually, or edit the top-level Makefile, replacing INIT_FILE with the appropriate location on your systemand QUEUED_USER with the username of a Freeside user you created above, and run <tt>make install-init</tt>)
207   <li>Now proceed to the initial <a href="admin.html">administration</a> of your installation.
208 </ul>
209 </body>