newsletterlibrary.com

Top : Computers : Software : Operating Systems : Unix : BSD : OpenBSD :
Security

Websites
How to use X.509v3 certificates for authentication with OpenBSD's isakmpd.
site exerpt
How to use X.509v3 certificates for authentication with isakmpd.  This document is still under construction and the information is partly untested and might be completely wrong. Consider yourself warned. Preface This document is made available in the belief that it might be useful to someone. The author is not...
http://hem.passagen.se/hojg/isakmpd/

How to configure isakmpd on OpenBSD to use the PGPnet client.
site exerpt
 Choose and configure your client Greenbow VPN PGPnet SafeNet SoftRemote SSH Make sure your network design is compatible with running vpn Troubleshoot Mailing List OpenBSD IPsec Clients These pages are for people who wants to use IPsec clients with OpenBSD...
http://www.allard.nu/openbsd/

Usage guide for the IP Filter firewall software formerly included with OpenBSD.
http://www.obfuscation.org/ipf/

How to build a bridge for filtering and firewalling.
http://www.daemonnews.org/200103/ipf_bridge.html

Whitepaper by OpenBSD developers Angelos Keromytis and Jason Wright presented at USENIX Technical Conference, June 2000.
site exerpt
Transparent Network Security Policy Enforcement  This paper was presented at USENIX 2000 Annual Technical Conference and published in its proceedings....
http://www.thought.net/jason/bridgepaper/

Outline notes for the half-day tutorial presented at the O'Reilly Open Source Conference in Monterey, California on July 17, 2000.
site exerpt
Secure Internet Servers/Firewalls with OpenBSD: Table of Content  These note are the outline for the half-day tutorial on Secure Internet Servers/Firewalls with OpenBSD: Table of Content presented at the O'Reilly Open Source Conference in Monterey, California on July 17, 2000. This text is copyright by Ian Darwin, but...
http://www.openbsd.org/papers/oreilly2000/

How to configure and use the S/Key 'one-time password' scheme on OpenBSD.
site exerpt
Tika.Arnholm.nu  Key i praktiken kan man skapa en lista över de nästa lösenorden och ha med sig denna. På listan kan man stryka de lösen ord man matat in och på så sätt hålla listan uppdaterad. OpenBSD's Faq om S/Key S/Key...
http://tika.arnholm.nu/skey.html

IP Accounting package for IPFilter in OpenBSD.
site exerpt
IP Accounting package for IP Filter  This project is unmaintained. It is superceded by IP audit and IP audit-Web. Alternate choices include ipfm, NeTraMet, and iplog. Please use these packages! Using the count option of IP Filter, this small package will create web pages suitable for...
http://www2.empnet.com/ipacct/

Whitepaper from the University of Alberta on using OpenBSD to block unauthorized users on unprotected Ethernet jacks.
site exerpt
Dealing with Public Ethernet Jacks Switches, Gateways, and Authentication.  This paper describes the tools and techniques developed and deployed to address the problem of blocking unauthorized users on unprotected Ethernet jacks. Our solution is being deployed to control public labs at the University of Alberta during the summer of...
http://www.ualberta.ca/~beck/authgw.html

Introductory guide to implementing a firewall using OpenBSD.
http://homepages.gold.ac.uk/veghead/wot/openbsd.html

Tutorial on hardening and improving security on OpenBSD systems.
site exerpt
GeodSoft How-To: Hardening OpenBSD Internet Servers: Contents  Internet servers includes sections that apply to any UNIX system. Hardening is making a computer more secure by removing unneeded functions, restricting access and tracking changes and processes. It was revised to cover OpenBSD 3.0 on Dec. 15, 2001 and...
http://geodsoft.com/howto/harden/

Whitepaper presented at USENIX 99 by OpenBSD developers Theo de Raadt, Niklas Hallqvist, Artur Grabowski, Angelo D. Keromytis, and Niels Provos discussing the cryptography employed in OpenBSD.
site exerpt
USENIX Technical Program Abstract USENIX 99  Cryptographic mechanisms are an important security component of an operating system in securing the system itself and its communication paths. Indeed, in many situations, cryptography is the only tool that can solve a particular problem, e.g network-level security. While cryptography...
http://www.usenix.org/events/usenix99/deraadt.html

Whitepaper by OpenBSD developers Niels Provos and David Mazières discussing ways of building systems in which password security keeps up with hardware speeds.
site exerpt
USENIX Technical Program Abstract USENIX 99  Many authentication schemes depend on secret passwords. Unfortunately, the length and randomness of user-chosen passwords remain fixed over time. In contrast, hardware improvements constantly give attackers increasing computational power. As a result, password schemes such as the traditional UNIX user-authentication...
http://www.usenix.org/events/usenix99/provos.html

Configuration document on IPSec interoperations for Linux, OpenBSD and PGPNet.
site exerpt
How to setup IPsec for Linux, OpenBSD and Kame/*BSD  This document is always under construction and the information is partly untested and might be completely wrong. Consider yourself warned. Preface This HOWTO is Copyrighted 2000 2003 by Hans-Jrg Hxer. It can be distributed freely. It cannot be modified. If...
http://www.rommel.stw.uni-erlang...~hshoexer/ipsec-howto/HOWTO.html

Phrack article by route discussing how to harden OpenBSD for multiuser environments.
site exerpt
www.phrack.org  Monthhome about all articles all authors all comments download search submit article loopback commentaries editor in chief Phrack 54 download (207 kb, 1998-12-25) by route 1 Introduction txt)Phrack Staff 2 Phrack Loopback txt)Phrack Staff 3 Phrack Line Noise txt)various 4...
http://www.phrack.org/show.php?p=54&a=6

Documentation for the packet filter in OpenBSD 2.9 -current.
site exerpt
The OpenBSD PF HOWTO is dead, long live OpenBSD PF!  Internet account soon now (costs me 160 a year just to keep this stuff up) so please remove this page from your links collection. For more up-to-date information about configuring OpenBSD PF, please consult the OpenBSD FAQ or Daniel Hartmeier's...
http://www.inebriated.demon.nl/pf-howto/

'Plugging holes with your fingers' - a guide to configuring IPSEC in OpenBSD.
site exerpt
 I outlined one method for integrating Windows networks into a secure VPN with IPSEC and Samba. This time around I'm going to demonstrate an alternative method of achieving what is essentially the same functionality in a completely different way. Your...
http://default.co.yu/~bc/docs/ipsec_bridging-1.txt

How to configure a basic VPN between two OpenBSD gateways using ISAKMP.
http://www.antioffline.com/ipsec/vpn/

This paper from Usenix 2002 describes the design of the new OpenBSD packet filter (pf) and compares performance of stateful vs. stateless filtering.
site exerpt
Design and Performance of the OpenBSD Stateful Packet Filter (pf)  Effort sponsored in part by the Defense Advanced Research Projects Agency (DARPA) and Air Force Research Laboratory, Air Force Materiel Command, USAF, under agreement number F30602-01-2-0537. Abstract With more and more hosts being connected to the Internet, the importance of...
http://www.benzedrine.cx/pf-paper.html