项目作者: redeltaglio

项目描述 :
Configuration of an OpenBSD rugged secured server to obtain a private CA for SSL and SSH
高级语言: Shell
项目地址: git://github.com/redeltaglio/OpenBSD-private-CA.git
创建时间: 2021-04-15T07:35:39Z
项目社区:https://github.com/redeltaglio/OpenBSD-private-CA

开源协议:Creative Commons Zero v1.0 Universal

下载


OpenBSD SSH, SSL and IKED CA server

img

Configuration of an OpenBSD rugged secured server to obtain a private CA for SSH, SSL and iked.

Reverse a private server, kvm instance, docker or another container for this type of application. It’ll be useful have it on a spare encrypted USB disk or virtual hided disk. I’ve got one mounted on a dedicated macppc OpenBSD instance. I use it like local LAN resolver, SNMP collector and, how not, like a CA server.

  1. taglio@cyberanarkhia:/home/taglio$ uname -a
  2. OpenBSD cyberanarkhia.telecom.lobby 6.8 GENERIC.MP#3 macppc
  3. taglio@cyberanarkhia:/home/taglio$

CA server

No everyone know it, but sshd as ssl can use certificate based authentication. It’s a feature of openssh.

Just clone this repository on the OpenBSD CA server machine:

  1. $ mkdir -p Sources/Git
  2. $ cd Sources/Git
  3. $ git clone https://github.com/redeltaglio/OpenBSD-private-CA.git
  4. $ cd OpenBSD-private-CA

Our setup_node script got some options:

  • install -> create SSH and SSL private CA
  • verify -> printout and verify certificates
  • reset -> reset filesystem hierarchy and delete certificates and keys
  • transfer -> tar files on /home/$USER

Nice Regards,

Riccardo <taglio> Giuntoli.