<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>James&#039; Tools and Tricks &#187; noacl</title>
	<atom:link href="http://jrudd.org/tag/noacl/feed/" rel="self" type="application/rss+xml" />
	<link>http://jrudd.org</link>
	<description>Tools, Tips and Hints for managing a network.</description>
	<lastBuildDate>Sun, 08 Jan 2012 03:50:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Using BackupPC with DiskShadow to backup open files</title>
		<link>http://jrudd.org/2010/07/using-backuppc-with-diskshadow-to-backup-open-files/</link>
		<comments>http://jrudd.org/2010/07/using-backuppc-with-diskshadow-to-backup-open-files/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 14:59:48 +0000</pubDate>
		<dc:creator>James Rudd</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Utilities]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Administrator]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[backuppc]]></category>
		<category><![CDATA[Cygwin]]></category>
		<category><![CDATA[DiskShadow]]></category>
		<category><![CDATA[noacl]]></category>
		<category><![CDATA[openssh]]></category>
		<category><![CDATA[rsync]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[server 2008 R2]]></category>
		<category><![CDATA[snapshots]]></category>
		<category><![CDATA[Task Scheduler]]></category>
		<category><![CDATA[VShadow]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://jrudd.org/wordpress/?p=151</guid>
		<description><![CDATA[This post is to assist in the setup of a BackupPC system able to backup in use files by using MS volume snapshots. It also has the benefit of only having the RSync daemon running during the backup which increases security.]]></description>
			<content:encoded><![CDATA[
<h1>Introduction</h1>
<p>This post is to assist in the setup of a BackupPC system able to  backup in use files by using MS volume snapshots. It also has the  benefit of only having the RSync daemon running during the backup which  increases security.</p>
<p>This method is based on some other posts I  have seen using <a href="http://www.goodjobsucking.com/?p=62">VShadow</a>, <a href="http://www.goodjobsucking.com/?p=62"><em>Backing Up Open Files on Windows with Rsync</em></a>, and some  suggestions on <a href="http://www.goodjobsucking.com/?p=62&amp;cpage=2#comment-3159">DiskShadow</a> but goes further in using RSync as a system service giving full access  to files, and removing the need to use winexe.</p>
<h2>General Outline</h2>
<ol>
<li>Create a new user <em><strong>backuppc </strong></em>(try to match case of the user on Linux). Very limited rights</li>
<li>Install Cygwin with RSync, OpenSSH and configure them</li>
<li>Create a scheduled task to run as SYSTEM when triggered by a certain event</li>
<li>Set BackupPC server for passwordless login to host and modify Pre/Post Dump Cmds</li>
</ol>

<h1>Overview</h1>
<p>In Windows 7 and Server 2008 R2 elevation is required to create snapshots. As a remote SSH connection cannot bypass UAC a way is needed to create the snapshot, bypassing the elevation prompt. I also wished to run the Rsync Daemon as SYSTEM user so it has rights to view all files.</p>
<p>To do this I moved all the elevated tasks into a Task Scheduler item that is set to run as SYSTEM, and is triggered by an Event log event.</p>
<ol>
<li>BackupPC performs a password-less key SSH logon to client</li>
<li>It runs a script which creates an event log entry and then waits for RSync to start before returning to BackupPC and starting the backup.</li>
<li>Task scheduler is triggered by <a href="http://support.microsoft.com/kb/315410">Event Log</a> and starts DiskShadow as SYSTEM.</li>
<li>Disk shadow creates a shadow of any chosen volumes, mounts them and then starts RSync.<br />
It then waits for a file to be created by BackupPC at the end of the backup telling it to stop RSync and delete the snaphots.</li>
</ol>
<h3>Flow and triggers</h3>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td width="205" valign="top"><strong>BackupPC Server</strong></td>
<td colspan="2" width="411" valign="top"><strong>Host PC</strong></td>
</tr>
<tr>
<td width="205" valign="top"><strong>backuppc User</strong></td>
<td width="205" valign="top"><strong>backuppc User</strong></td>
<td width="205" valign="top"><strong>SYSTEM</strong></td>
</tr>
<tr>
<td style="text-align: center;" colspan="3" width="411" valign="top"><strong>Start Backup</strong></td>
</tr>
<tr>
<td width="205" valign="top">SSH to Host PC</td>
<td width="205" valign="top"></td>
<td width="205" valign="top"></td>
</tr>
<tr>
<td width="205" valign="top"></td>
<td width="205" valign="top">Log Event</td>
<td width="205" valign="top">Diskshadow: Snaphsot</td>
</tr>
<tr>
<td width="205" valign="top"></td>
<td width="205" valign="top"></td>
<td width="205" valign="top">Start Rsync</td>
</tr>
<tr>
<td width="205" valign="top"></td>
<td width="205" valign="top">Close and return</td>
<td width="205" valign="top"></td>
</tr>
<tr>
<td width="205" valign="top">Begin Backup</td>
<td width="205" valign="top"></td>
<td width="205" valign="top"></td>
</tr>
<tr>
<td style="text-align: center;" colspan="3" width="411" valign="top"><strong>Finish Backup</strong></td>
</tr>
<tr>
<td width="205" valign="top">SSH to Host PC</td>
<td width="205" valign="top"></td>
<td width="205" valign="top"></td>
</tr>
<tr>
<td width="205" valign="top"></td>
<td width="205" valign="top">Create a Wake.up file</td>
<td width="205" valign="top"></td>
</tr>
<tr>
<td width="205" valign="top"></td>
<td width="205" valign="top"></td>
<td width="205" valign="top">Stop Rsync</td>
</tr>
<tr>
<td width="205" valign="top"></td>
<td width="205" valign="top"></td>
<td width="205" valign="top">Delete Snaphost</td>
</tr>
</tbody>
</table>
<h1>Host PC</h1>
<p>Create a new user, <em><strong>backuppc</strong></em>, you can limit this account further in Security policy after everything is configured.</p>
<p>Create a BackupPC folder and add the following scripts to it. These are also available in a <a href="http://jrudd.org//download/general/BackupPC-Config.zip">zip file</a>. Note: There is a file embedded within this post, please visit this post to download the file. You will need to modify paths depending on where you create the folder. I used C:\cygwin\BackupPC but a better location may be C:\cygwin\usr\share\BackupPC</p>
<p>Most of these scripts are just modified versions of the ones written for <a href="http://www.goodjobsucking.com/?p=62">VShadow</a>, changed to work with DiskShadow and Task Scheduler.</p>
<p><strong>pre-cmd.vbs</strong></p>
<pre class="brush: vb; collapse: true; light: false; title: ; toolbar: true; notranslate">' This file starts the commands
' It will start the snapshot process and quite once RSync is running

Const Rsync = &quot;C:\cygwin\var\run\rsyncd.pid&quot;
Const Flag = &quot;C:\cygwin\var\run\wake.up&quot;
Set fso = CreateObject(&quot;Scripting.FileSystemObject&quot;)
'
' Pid file shouldn't be there already
' Check /stop service , still there delete
'
If DoesFileExist(Rsync)=0 Then
	fso.DeleteFile(Rsync)
End If
'
' Nor should &quot;wake.up&quot;
'
If DoesFileExist(Flag)=0 Then
   fso.DeleteFile(Flag)
End If

Set objShell = CreateObject(&quot;WScript.Shell&quot;)
' objShell.Exec &quot;C:\BackupPC\backuppc.cmd &gt; &quot; &amp; Log

' This writes event log entry that triggers task scheduler to start system process
' that takes snapshot and starts RSync
objShell.Exec &quot;Logevent.exe -r &quot;&quot;BackupPC&quot;&quot; -e 10 -s S &quot;&quot;Backup Start&quot;&quot; &quot;
Wscript.Echo &quot;Sent BackupPC Event Log Trigger&quot;

'
' Just sleep until the file &quot;rsyncd.pid&quot; appears
'

While DoesFileExist(Rsync)
   wscript.sleep 10000
Wend

' functions

function DoesFileExist(FilePath)
Dim fso
	Set fso = CreateObject(&quot;Scripting.FileSystemObject&quot;)
	if not fso.FileExists(FilePath) then
		DoesFileExist = -1
	else
		DoesFileExist = 0
	end if
	Set fso = Nothing

end function</pre>
<p><strong>backuppc.cmd</strong></p>
<pre class="brush: plain; collapse: true; light: false; title: ; toolbar: true; notranslate">c:
cd C:\cygwin\BackupPC
diskshadow /s DiskShadowScript.txt /l C:\cygwin\var\log\diskshadow.log
del C:\cygwin\var\tmp\*.cab /q
c:cd C:\cygwin\BackupPCdiskshadow /s DiskShadowScript.txt /l C:\cygwin\var\log\diskshadow.log
del C:\cygwin\var\tmp\*.cab /q</pre>
<p><strong>DiskShadowScript.txt</strong></p>
<pre class="brush: plain; collapse: true; light: false; title: ; toolbar: true; notranslate">#DiskShadow script file

#Make shadows persistent, No writers as data volume

# If backing up C: and any app files (ntds, database, etc) use writers

#SET CONTEXT PERSISTENT NOWRITERS

SET CONTEXT PERSISTENT

#Cab location for process

SET METADATA C:\cygwin\var\tmp\backup.cab

SET VERBOSE ON

BEGIN BACKUP

#Alias volume with alias

ADD VOLUME C: ALIAS SystemData

ADD VOLUME F: ALIAS UserData

#Create Snapshot

CREATE

#Expose the volume and run command file then unexpose

EXPOSE %UserData% B:

EXPOSE %SystemData% T:

EXEC C:\cygwin\BackupPC\Serverbackup.cmd

UNEXPOSE B:

UNEXPOSE T:

END BACKUP

#Delete the shadow copy

DELETE SHADOWS SET %VSS_SHADOW_SET%

#End of script</pre>
<p><strong>Serverbackup.cmd</strong></p>
<pre class="brush: plain; collapse: true; light: false; title: ; toolbar: true; notranslate">REM Start RSync now that Snapshots are created

net start rsyncd

REM Need to wait until backup completed

cscript &quot;C:\cygwin\BackupPC\sleep.vbs&quot;

Logevent.exe -r &quot;BackupPC&quot; -e 20 -s S &quot;Backup Completed&quot;
</pre>
<p><strong>sleep.vbs</strong></p>
<pre class="brush: vb; collapse: true; light: false; title: ; toolbar: true; notranslate">Const Rsync = &quot;C:\cygwin\var\run\rsyncd.pid&quot;
Const Flag = &quot;C:\cygwin\var\run\wake.up&quot;
Set fso = CreateObject(&quot;Scripting.FileSystemObject&quot;)

' Just sleep until the file &quot;rsyncd.pid&quot; appears
While DoesFileExist(Rsync)
   wscript.sleep 10000
Wend

' Now sleep until the file &quot;wake.up&quot; appears
While DoesFileExist(Flag)
   wscript.sleep 10000
Wend

fso.DeleteFile(Flag)

' It's time to kill Rsync
'Stop Service
strServiceName = &quot;rsyncd&quot;
Set objWMIService = GetObject(&quot;winmgmts:{impersonationLevel=impersonate}!\\.\root\cimv2&quot;)
Set colListOfServices = objWMIService.ExecQuery(&quot;Select * from Win32_Service Where Name ='&quot; &amp; strServiceName &amp; &quot;'&quot;)
For Each objService in colListOfServices
    objService.StopService()
	Wscript.Echo &quot;RSyncD Stopped&quot;
Next

' Wait for Rsync to let go
wscript.sleep 5000

' Delete PID file
If DoesFileExist(Rsync)=0 Then
   fso.DeleteFile(Rsync)
End If

' functions
function DoesFileExist(FilePath)
Dim fso
	Set fso = CreateObject(&quot;Scripting.FileSystemObject&quot;)
	if not fso.FileExists(FilePath) then
		DoesFileExist = -1
	else
		DoesFileExist = 0
	end if
	Set fso = Nothing

end function
</pre>
<h2>Cygwin</h2>
<p>Install Cygwin and choose to install packages RSync and OpenSSH</p>
<p>Start an elevated Cygwin (Run as an Administrator )</p>
<h4>Config</h4>
<p>Cygwin 1.7 changes the way to ignore NT Security from the <em>nontsec </em>environment to modifying fstab file.</p>
<p>In your prefered editor modify /etc/fstab and uncomment the bottom line and add <em>noacl </em>as below, this tells it to ignore security :</p>
<pre class="brush: plain; light: true; title: ; notranslate">none /cygdrive cygdrive binary,noacl,posix=0,user 0 0</pre>
<p>Run following to update group and user lists (if on a domain only add the users you want)</p>
<p>[bashlight=1]mkpasswd –l >/etc/passwd<br />
mkgroup –l /etc/group[/bash]</p>
<h3>OpenSSH</h3>
<p>Configure Open SSH using <em>ssh-host-config</em>, create both the accounts it suggests for privilege isolation and running the service (cyg_service &amp; sshd).<br />
This should also automatically add the Firewall Exceptions (SSHD).</p>
<h4>Setting up Keyless</h4>
<p><span style="font-weight: normal;">Login as backuppc user.</span><br />
<span style="font-weight: normal;"> </span><span style="font-weight: normal;">Use </span></p>
<pre class="brush: plain; light: true; title: ; notranslate">runas /user:backuppc cmd</pre>
<p>Or</p>
<pre class="brush: plain; light: true; title: ; notranslate">runas /user:domain\backuppc cmd</pre>
<p>Run c:\cygwin\Cygwin.bat to start Cygwin as BackupPC user</p>
<p>You need to add the id_rsa.pub file from the BackupPC user on BackupPC server to C:\cygwin\home\backuppc\.ssh\authorized_keys If you have not already created one follow the instructions below in BackupPC &#8211; SSH section.</p>
<h3>RSync</h3>
<p>To install RSync as a system service use:</p>
<pre class="brush: plain; title: ; notranslate">C:\cygwin\bin\cygrunsrv.exe -I rsyncd -d &quot;RSync Daemon&quot; -O --type manual -p /bin/rsync.exe -f &quot;Used by BackupPC to remotely access files for backup&quot; -a &quot; --config=/etc/rsyncd.conf --daemon --no-detach&quot;</pre>
<p>Modify the /etc/rsyncd.conf file to reflect what drives you want to backup. It is better to edit this file later after you have modified the DiskShadowScript.txt and changed which drive letter it exposes shadows as.</p>
<p>Add a RSync exception to the firewall.</p>
<p>Open <em>Windows Firewall with Advanced Security</em> and choose Inbound Rules, New Rule, Program,  Next</p>
<p>Browse to C:\cygwin\bin\rsync.exe and then choose your options and name the rule</p>
<p>When finished open the rule, click Scope tab and add a Remote IP, that of the BackupPC server. This restricts RSync to only be accessible from BackupPC. You may also wish to similarly modify SSHD to only allow SSH access from BackupPC server.</p>
<h2>DiskShadow</h2>
<p>If you are backing up a windows Server 2008 or 2008 R2 host you already have DiskShadow installed. However, if you are running Windows 7 or Vista you will need to grab a copy from an equivalent server (x86 or x64). It is located in the System32 directory and you will also need the language file from the en-US folder.</p>
<p>I have <a href="http://jrudd.org//download/utilities/DiskShadow.zip">zipped the files needed</a> for x86 and x64 if you do not have immediate access to a Server.Note: There is a file embedded within this post, please visit this post to download the file. (The x86 files are from Server 2008 and x64 are from 2008 R2)</p>
<p>Copy the files from your architecture to the system32 directory and en-US subdirectory.</p>
<h3>LogEvent</h3>
<p>To generate the custom event log entry a tool from the Windows 2000 Resource kit is used, <a href="http://support.microsoft.com/kb/315410">LogEvent</a>, (<a href="http://www.dynawell.com/download/reskit/microsoft/win2000/logevent.zip">Download</a>). This needs to be either placed in the Path (e.g. Windows dir) or scripts need to directly call it.</p>
<h2>Task Scheduler</h2>
<p>The easiest way to configure this is to manually run LogEvent once to generate an event in the log.</p>
<pre class="brush: plain; light: true; title: ; notranslate">Logevent.exe -r &quot;BackupPC&quot; -e 10 -s S &quot;Backup Start&quot;</pre>
<p>Then open Event Viewer, Select the new BackupPC event and choose <em>Attach Task to this Event</em>, and in the wizard click next until it asks for the program, then give it <strong>C:\cygwin\BackupPC\backuppc.cmd</strong></p>
<p>On Final page choose to <em>Open Properties</em> when you click Finish</p>
<p>Click the <em>Change User or Group</em> button and type in <strong>System </strong>as the user  and click OK. Also tick the <em>Run with highest privileges</em> box</p>
<h1>BackupPC Server</h1>
<h2>SSH</h2>
<p>This section is only needed if you do not already have keys generated for the backuppc user.</p>
<p>Login as backuppc user, either with password or simply “su – backuppc” from root</p>
<p>Generate SSH Keys, <span style="font-family: Consolas, Monaco, 'Courier New', Courier, monospace; line-height: 18px; font-size: 12px; white-space: pre;"><em>ssh-keygen –t rsa</em></span>, do not set a password. Copy id_rsa.pub into C:\cygwin\home\backuppc\.ssh \authorized_keys</p>
<p>Test by running <em>ssh -v backuppc@host</em> to test the connection</p>
<h2>BackupPC Host File</h2>
<p>In the web interface change the following for the host.</p>
<pre class="brush: plain; light: true; title: ; notranslate">DumpPreUserCmd:  $sshPath -q -x -l backuppc $host cscript &quot;C:\cygwin\BackupPC\pre-cmd.vbs&quot;
 DumpPostUserCmd: $sshPath -q -x -l backuppc $host echo &quot;Complete: $xferOK&quot; &gt; /var/run/wake.up</pre>
<h2>Test Run</h2>
<p>If you have existing backups from a previous RSync config, it is a good idea to run a full backup to ensure any in use files are part of the base. In my case I also changed the <em>noacl </em>flag which affected the file attributes RSync sees.</p>
<h1>Tips</h1>
<p>Set your antivirus to exclude the exposed drives. As they are read only it just slows down the reading of files by RSync.</p>
<h3>Downloads</h3>
Note: There is a file embedded within this post, please visit this post to download the file.
<h1>Updates</h1>
<ul>
<li>While writing this up I found a good alternative way of using VShadow with SSH to backup in use files, that uses the AT command instead of task scheduler to get around UAC, <a href="http://geraldbrandt.com/2010/06/08/backuppc-with-sshrsyncvss-on-windows-server/">BackupPC with ssh/rsync/VSS on Windows Server</a>. The only down side to this method is the SSH connection requires an Admin account, but if configured securely this should be fine. It also a lot simpler to configure as it does not require configuring Task Scheduler.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://jrudd.org/2010/07/using-backuppc-with-diskshadow-to-backup-open-files/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

