Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

23 June 2015

Using PEAP for wireless authentication

PEAP creates an encrypted TLS tunnel between the client and the authentication server. The keys for this encryption are transported using the server's public key. The ensuing exchange of authentication information inside the tunnel to authenticate the client is then encrypted and user credentials are safe from eavesdropping.

Use a trusted certificate for authentication: The RADIUS server must be configured with a digital certificate that is signed by a trusted certificate authority (CA), using a private or a public CA.
Validate the server certificate on all clients: All PEAP clients must validate the server certificate for authentication. A Trusted Root CA, that issued the server certificate, must be installed in client.








Reference:
http://www.networkworld.com/columnists/2007/042307-wireless-security.html
http://revolutionwifi.blogspot.com/2010/09/peapv0-packet-flow-reference.html
http://www.keyboardlife.net/2010/06/8021x-port-based-authentication-wired.html

20 July 2011

wpa_passphrase

WPA-PSK uses pre-shared key as a passphrase of 8 to 63 printable ASCII characters or as a string of 64 hexadecimal digits.

If ASCII characters are used, the 256 bit key is calculated by applying the PBKDF2 key derivation function to the passphrase, using the SSID as the salt and 4096 iterations of HMAC-SHA1.

wpa_passphrase -- utility for generating a 256-bit pre-shared WPA key from an ASCII passphrase. You can download wpa_passphrase.tar.gz from here.
# tar xzvf wpa_passphrase.tar.gz
# make
# ./wpa_passphrase humble mypassword
network={
ssid="humble"
#psk="mypassword"
psk=aa382e1c4ac62580c25ee2b33a1cf6179176baad4a5cffc43be9c8d2b103f4aa
}
AP can be configured with ASCII passphrase or HEX digits
Which enables the windows client to uses either of the above key
For home and small office networks its preferred to use WPA2-personal authentication method which also uses CCMP, AES based encryption.
Each wireless network device authenticates with the access point using the same 256-bit key.

Reference:
http://www.hautespot.net/wpapsk.html
http://fuse4bsd.creo.hu/localcgi/man-cgi.cgi?wpa_passphrase+8

23 July 2010

encrypt/decrypt with openssl

# echo "hi there" > test
# openssl aes-128-cbc -in test -base64 -k password
U2FsdGVkX18mc7Sq6Q3CqPVbNe3Kp7Pyqr2sDo7rQTE=

# openssl aes-128-cbc -in test -base64 -k password > test.enc
# openssl enc -d -in test.enc -k password
U2FsdGVkX18z0h1BxcQtiQ7Fq7xKnabTC8fZnmw1bOE=

# openssl aes-128-cbc -d -in test.enc -k password -base64
hi there
# echo -n "" | md5sum
d41d8cd98f00b204e9800998ecf8427e
# echo -n "hi there" | md5sum
fd33e2e8ad3cb1bdd3ea8f5633fcf5c7

Reference:
http://www.cs.colorado.edu/~jrblack/class/csci6268/f05/slides/CSCI6268L12.ppt
http://www.mydigitallife.info/2008/12/10/how-to-calculate-and-generate-md5-hash-value-in-linux-and-unix-with-md5sum

10 January 2010

iptables mystery - 2

Find "iptables mystery" first part here.

There are three tables (queues):
1. mangle table - which is responsible for the alteration of "qos" bits in the TCP header.
2. filter queue - which is responsible for packet filtering.
2.a. Input chain: Filters packets destined for the firewall.
2.b. Output chain: Filters packets originating from the firewall.
2.c. Forward chain: Filters packets to servers protected by the firewall.
3. nat queue - which is responsible for network address translation.
3.a. Pre-routing chain: NATs packets when the destination address of the packet needs to be changed.
3.b. Post-routing chain: NATs packets when the source address of the packet needs to be changed
#!/bin/sh
#nat.sh

# flush and delete all non-buildin chains
nat-flush.sh

# eth0 is connected to the internet
# eth1 is connected to a private LAN
# Set up IP FORWARDing and Masquerading
iptables -t filter -A FORWARD -i eth1 -o eth0 -j ACCEPT
iptables -t filter -A FORWARD -i eth0 -o eth1 -j ACCEPT
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

echo 1 > /proc/sys/net/ipv4/ip_forward
#!/bin/sh
#nat-flush.sh

echo "Stopping firewall and allowing everyone..."

# flush all chains (INPUT, OUTPUT, FILTER, ...)
iptables -t filter -F
iptables -t nat -F
iptables -t mangle -F

# delete all non-buildin chains in the table
iptables -t filter -X
iptables -t nat -X
iptables -t mangle -X

iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -Z //Zero packet and byte counters in all chains.
iptables -L -v //List all rules in in the chains.

//Reject ping with reply "Host Unreachable"
1. chkconfig rsyslog on
2. service rsyslog restart
3. iptables -t filter -A INPUT -p icmp -j LOG
4. iptables -t filter -A INPUT -p icmp -j REJECT \
--reject-with icmp-host-unreachable
5. tail -f /var/log/messages

6. chkconfig iptables on
7. service iptables save // /etc/sysconfig/iptables


Reference:
Firewalls_Using_iptables
Linux Tutorial Iptables Network Gateway

21 August 2009

Secure Network Access

NAC stands for Network Access Control.
802.1X is the IEEE standard for port-based network access control.

NAC provides Endpoint security. The end point device can be a Laptop connected to a corporate network or a VPN client.
Depending on the security policy NAC will do user authentication, periodic health checks and policy enforcement.

-> User authentication can be by portal login, 802.1x etc.
-> Health check is done by a custom made Java applet, which runs on client, collect useful device information. Microsoft’s built-in NAP client also does the same job.
-> Policy enforcement, the most important part in a NAC, is done by SSCP, SSCPLite (Nortel proprietary), 802.1x etc.

=> NAC creates database with the information forwarded by NAC client. The policy decision is made based on corporate policy and database information. NAC server is also known as Policy Decision Point.

=> Policy enforcement point can be Switch, router, VPN gateway or firewall. Most commonly used access control techniques are VLAN segregation and packet filtering ACLs.

Future of NAC:
Some NAC policy servers are:
1. Cisco's Access Control Server (ACS)
2. Juniper's Unified Access Controller (UAC)
3. Microsoft's Network Policy Server (NPS)
4. Nortel's Secure Network Access (NSNA)
5. Trusted Computing Group's Trusted Network Connect (TNC)

IF-MAP is a standard client/server, XML-based SOAP, protocol for accessing a Metadata Access Point. The IF-MAP server has a database for storing information about network security events and objects (users, devices, etc.). The IF-MAP protocol defines a powerful publish/subscribe/search mechanism and an extensible set of identifiers, and data types.





=> Integrity measurements are carried between the TNC Client and TNC Server on a protocol called IF-TNCCS (Trusted Network Connect Client-Server).
=> For communication with NAP Client and NAP Server Microsoft used protocol called System of Health (SoH). Later donated to TCG as IF-TNCCS-SOH.

=> Consolidated IF-TNCCS enables Client-Server interoperability between NAP and TNC.
=> industry has agreed on TNC standard for NAC, except Cisco.

Reference:
White Paper - 1
http://features.techworld.com/networking/4073/microsoft-gets-nac-act-together
http://www.isp-planet.com/technology/2007/nac_3c.html
http://www.trustedcomputinggroup.org/developers/trusted_network_connect

802.1x

PPP is a data link protocol commonly used to establish a direct connection between two networking nodes.
PPP can provide connection authentication, transmission encryption privacy, and compression.

PPP -> alone provides username/password authentication (CHAP, PAP)
PPP + EAP -> Any type of authentication (EAP-MD5, PEAP)
PPP + EAP + RAS -> works fine
PPP + EAP + RAS + AAA -> RADIUS protocol takes care of the authentication
EAPOL + RAS + AAA -> 802.1x


L2TP and Microsoft’s secure RAS made PPP popular.
EAP is a universal authentication framework.
EAPOL is a standard for passing EAP over LAN.


802.1x is an IEEE standard for Port-Based Network Access Control.
802.1x works at Layer 2 to authentication and authorize devices on LAN switches and wireless APs.
It won’t work with multiple PC's connecting to a switch via a hub.

-> The user/client that wants to be authenticated is called a supplicant.
-> The actual server doing the authentication, typically a RADIUS server, is called the authentication server.
-> And the device in between, such as a wireless access point, is called the authenticator.



Benefits of IEEE 802.1X
1. Leverages existing standards EAP and RADIUS
2. Authentication based on Network Access Identifier and credentials
3. Centralized authentication, authorization, and accounting
4. Scalable through EAP types
5. Supports password authentication and One-Time Passwords (OTP)

Configure Freeradius:
/etc/raddb/clients.conf -> "client localhost { secret = testing }"
/etc/raddb/users -> "user1 User-Password := "pass1""
/sbin/radiusd -X
/bin/radtest user1 pass1 localhost 0 testing


Configure Switch (Nortel ERS 4550):
vlan members remove 1 1-11
vlan members add 16 1-11
vlan ports 12 tagging enable

radius-server host 192.168.10.254
radius-server key "testing"
radius-server port 1812

eapol enable
##EAPOL Administrative Status #> ENABLE
##EAPOL Administrative Status for ports #> Auto


Configure PC:
enable the following windows services:
-> Extensible Authentication Protocol Service
-> Wired AutoConfig / Wireless Zero Configuration

Local Area Connection properties -> Authentication -> Enable IEEE 802.1x authentication
Local Area Connection properties -> Authentication -> network auth method -> Protected EAP
Local Area Connection properties -> Authentication -> settings -> Authentication method -> EAP-MSCHAP v2



Reference:
http://www.javvin.com/protocol8021X.html
http://www.netcraftsmen.net/welcher/papers/dot1x.html
http://www.ipv6.com/articles/wireless/8021x-Wireless.htm
http://www.zyxeltech.de/SNotep335wt/app/8021x.htm
http://en.opensuse.org/RadiusServerHOWTO
http://www.ibm.com/developerworks/library/l-radius/

05 August 2009

openssl and certificates

Download the latest openssl source from here (0.9.8k).

1.3.6.1.4.1.311.20.2.2 - Smart Card Logon
1.3.6.1.4.1.311.20.2.3 - UPN (User Principal Name)

Certificate extentions:
.pem - (Privacy Enhanced Mail) Base64 encoded DER certificate, 
enclosed between "-----BEGIN CERTIFICATE-----"
and "-----END CERTIFICATE-----"

.cer, .crt, .der - usually in binary DER form,
but Base64-encoded certificates are common too

.p7b, .p7c - PKCS#7 SignedData structure without data,
just certificate(s) or CRL(s)

.p12 - PKCS#12, may contain certificate(s) (public)
and private keys
(password protected)
(Personnal Information Exchange)
Generate CA key and Certificate:
openssl genrsa -out ca.key 1024

openssl req -new -x509 -days 365 \
-subj '/C=IN/ST=KA/L=BL/O=Nortel/OU=Eng/CN=localhost ca' \
-key ca.key -out ca.crt
Generate server key and certificate:
openssl genrsa -out server.key 1024

openssl req -new \
-subj '/C=IN/ST=KA/L=BL/O=Nortel/OU=Eng/CN=localhost' \
-key server.key -out server.csr

cat > server.cnf << EOF
[dir_sect]
keyUsage=digitalSignature,keyEncipherment
subjectKeyIdentifier=hash
authorityKeyIdentifier=keyid,issuer
subjectAltName=otherName:1.3.6.1.4.1.311.20.2.3;UTF8:humble@yahoo.com
EOF

openssl x509 -req -days 365 -in server.csr \
-CA ca.crt -CAkey ca.key \
-extfile server.cnf -extensions dir_sect -set_serial 01 -out server.crt
Verify and show the server generated certificate:
# openssl pkcs12 -export -out server.p12 -inkey server.key -in server.crt
# openssl req -in server.csr -noout -verify -key server.key
# openssl x509 -noout -text -in server.crt
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 1 (0x1)
Signature Algorithm: sha1WithRSAEncryption
Issuer: C=IN, ST=KA, L=BL, O=Nortel, OU=Eng, CN=localhost ca
Validity
Not Before: Jul 27 09:23:44 2010 GMT
Not After : Jul 27 09:23:44 2011 GMT
Subject: C=IN, ST=KA, L=BL, O=Nortel, OU=Eng, CN=localhost
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public Key: (1024 bit)
Modulus (1024 bit):
00:d3:d4:a6:31:55:20:94:38:a8:72:16:eb:b8:2a:
9a:7c:07:98:36:63:7c:3c:f7:ad:ff:ad:27:4b:9b:
38:85:92:e5:44:07:12:1e:e3:b7:e9:09:d2:67:01:
71:51:50:fc:a7:7f:ec:72:2c:30:f4:24:0b:68:fa:
c4:7e:56:7b:70:dd:c4:50:7a:8c:51:d5:7f:46:a1:
02:7f:76:d8:6f:2c:79:48:57:9b:6f:fa:06:2d:dd:
5c:e6:f0:74:57:0a:85:85:39:a0:ce:36:64:2a:b1:
7b:1e:26:aa:df:c5:8f:93:6b:e6:02:cb:8d:f8:44:
89:37:58:31:cd:83:68:3a:87
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Key Usage:
Digital Signature, Key Encipherment
X509v3 Subject Key Identifier:
CF:36:42:69:6D:85:D4:D6:22:F8:6F:45:DD:EC:74:...
X509v3 Authority Key Identifier:
keyid:55:B0:22:DC:4F:4C:21:AA:69:EA:47:31:A2:...

X509v3 Subject Alternative Name:
othername:
Signature Algorithm: sha1WithRSAEncryption
de:ff:04:5c:82:e5:74:3c:75:d0:80:21:c7:5b:74:21:91:5b:
07:cb:5a:9e:6d:46:ae:5d:1d:69:26:5a:44:ec:b5:ad:25:72:
a5:5d:f1:e9:b5:45:14:2c:98:b6:40:5f:b8:e8:92:ba:a5:0c:
34:86:0e:20:51:25:64:6a:f7:cf:33:ec:50:f8:eb:9f:59:de:
99:b5:c1:75:cd:d2:ff:00:c0:ed:b2:30:44:f2:1e:13:75:dd:
21:da:f7:7f:bd:3c:60:7a:f6:66:44:c1:c9:b4:b6:75:ac:59:
07:c3:e5:06:eb:97:b2:64:0c:f2:2c:2c:39:b1:35:a6:19:b6:
a6:50

The certificate "server.crt" in windows:


Reference:
make-certs.sh
http://www.madboa.com/geek/openssl
http://en.wikipedia.org/wiki/X.509

30 July 2009

Setting up SSL and Apache

Setup the WampServer as explained here

------------------Generate your own CA------------------
1. Generate a ca key:
openssl genrsa -des3 -out ca.key 1024

2. Generate a ca certificate:
openssl req -new -x509 -days 365 -key ca.key -out ca.crt
subject=/C=IN/ST=Karnataka/L=Bangalore/O=Nortel/OU=Engineering/CN=localhostca

3. Generate a server key:
openssl genrsa -des3 -out server.key 1024

4. Create a certificate signing request:
openssl req -new -key server.key -out server.csr
subject=/C=IN/ST=Karnataka/L=Bangalore/O=Nortel/OU=Engineering/CN=localhost

5. Sign the certificate signing request:
openssl x509 -req -days 365 -in server.csr -CA ca.crt -CAkey ca.key -set_serial 01 -out server.crt

6. Create an insecure version of the server.key:
openssl rsa -in server.key -out server.key.insecure
mv server.key.insecure server.key

openssl req -noout -text -in server.csr
openssl x509 -noout -text -in server.crt

server.crt: The self-signed server certificate.
server.key: The private server key.
ca.crt: The Certificate Authority's own certificate.
--------------------------------------------------------

1. Update "C:\Program Files\wamp\bin\apache\Apache2.2.11\conf\httpd.conf"
-> LoadModule ssl_module modules/mod_ssl.so
-> Include conf/extra/httpd-ssl.conf
2. Update "C:\Program Files\wamp\bin\apache\Apache2.2.11\conf\extra\httpd-ssl.conf"
-> #DocumentRoot "C:/Program Files/Apache Software Foundation/Apache2.2/htdocs"
-> SSLCertificateFile "C:/Program Files/Apache Software Foundation/Apache2.2/conf/server.crt"
-> SSLCertificateKeyFile "C:/Program Files/Apache Software Foundation/Apache2.2/conf/server.key"
3. Copy server.crt and server.key to "C:\Program Files\Apache Software Foundation\Apache2.2\conf"
4. Restart Apache server
5. Copy ca.crt to:
-> Mozilla Tools >> Options >> Advanced >> Encryption >> Veiw Certificates >> Authorities
-> IE Tools >> Internet Options >> Content >> Certificates >> Trusted Root Certification Authorities

If https://localhost is not working then refer the logs at "C:\Program Files\Apache Software Foundation\Apache2.2\logs"

Reference:
http://middleware.its.state.nc.us/middleware/Documentation/en_US/htm/csqzas00/csqzas000p.htm
http://progtutorials.tripod.com/SSL.htm
http://www.tc.umn.edu/~brams006/selfsign.html
http://www.tc.umn.edu/~brams006/selfsign_redhat.html
http://articles.techrepublic.com.com/2415-3513_11-167032.html

14 June 2009

iptables mystery

Iptables is the firewall and packet filtering replacement for Ipchains in the Linux 2.4 kernel.
Iptables is the user space tool used to configure the packet filtering and NAT rules within the kernel.

Each table contains a number of built-in chains and may also contain user-defined chains. Each chain is a list of rules which specifies what to do with a packet that matches.



iptables -A INPUT -p tcp --dport 22 -s 192.168.10.160 -j REJECT

This command appends a chain to the table FILTER and chain INPUT, the rule instructs to drop all the tcp packets coming to port 22 from machine 192.168.10.160.


iptables –N SSH
iptables –A SSH –p tcp –s 192.168.10.160 –j LOG
iptables –A SSH –p tcp –s 192.168.10.160 –j REJECT
iptables –A SSH –j ACCEPT

iptables –A INPUT –p tcp --dport 22 –j SSH

This set of commands creates an SSH chain and add set of rules to it. It tells to LOG and REJECT the connection coming from 192.168.10.160, and to ACCEPT all the other connections.
Finally all the tcp packets to the port 22 reaching FILTER table and INPUT chain are forwarded to SSH chain.

Reference:
http://www.frozentux.net/iptables-tutorial/chunkyhtml