<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt DokuWiki" -->
<?xml-stylesheet href="http://asyd.net/home/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="http://asyd.net/home/feed.php">
        <title>asyd.net docs:security</title>
        <description></description>
        <link>http://asyd.net/home/</link>
        <image rdf:resource="http://asyd.net/home/lib/images/favicon.ico" />
       <dc:date>2011-06-19T17:00:06+02:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://asyd.net/home/docs/security/cas"/>
                <rdf:li rdf:resource="http://asyd.net/home/docs/security/certificates"/>
                <rdf:li rdf:resource="http://asyd.net/home/docs/security/kerberos"/>
                <rdf:li rdf:resource="http://asyd.net/home/docs/security/openssl"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="http://asyd.net/home/lib/images/favicon.ico">
        <title>asyd.net</title>
        <link>http://asyd.net/home/</link>
        <url>http://asyd.net/home/lib/images/favicon.ico</url>
    </image>
    <item rdf:about="http://asyd.net/home/docs/security/cas">
        <dc:format>text/html</dc:format>
        <dc:date>2008-10-03T08:25:38+02:00</dc:date>
        <title>docs:security:cas</title>
        <link>http://asyd.net/home/docs/security/cas</link>
        <description>CAS (Central Authentication Service) is a Java J2EE application
to bring SSO on existing web applications. 

Configuration

	*  X509 Authentication</description>
    </item>
    <item rdf:about="http://asyd.net/home/docs/security/certificates">
        <dc:format>text/html</dc:format>
        <dc:date>2006-09-11T11:33:06+02:00</dc:date>
        <title>docs:security:certificates</title>
        <link>http://asyd.net/home/docs/security/certificates</link>
        <description>Glossary

	*  X509 Attributs
	*  PKCS (Public Key Cryptography Standards)

Some example of CA policy

	*  Mozilla CA Certificate Policy</description>
    </item>
    <item rdf:about="http://asyd.net/home/docs/security/kerberos">
        <dc:format>text/html</dc:format>
        <dc:date>2005-11-14T19:29:44+02:00</dc:date>
        <title>docs:security:kerberos</title>
        <link>http://asyd.net/home/docs/security/kerberos</link>
        <description>Enctypes


kdc logs use decimal value to refer encrypt types

Extract from kr5b.conf



/* per Kerberos v5 protocol spec */
#define ENCTYPE_NULL            0x0000
#define ENCTYPE_DES_CBC_CRC     0x0001  /* DES cbc mode with CRC-32 */
#define ENCTYPE_DES_CBC_MD4     0x0002  /* DES cbc mode with RSA-MD4 */
#define ENCTYPE_DES_CBC_MD5     0x0003  /* DES cbc mode with RSA-MD5 */
#define ENCTYPE_DES_CBC_RAW     0x0004  /* DES cbc mode raw */
/* XXX deprecated? */
#define ENCTYPE_DES3_CBC_SHA    0x000…</description>
    </item>
    <item rdf:about="http://asyd.net/home/docs/security/openssl">
        <dc:format>text/html</dc:format>
        <dc:date>2006-10-26T09:05:00+02:00</dc:date>
        <title>docs:security:openssl</title>
        <link>http://asyd.net/home/docs/security/openssl</link>
        <description>Initialization

Generate the CA private key


# openssl genrsa -out ca.key 2048


or 


# openssl gendsa -out ca.key 2048


Generate the initial CSR


# openssl req -new -config ca.req.cnf -out cacert.pkcs10 -keyfile ca.key


Selfsign the CSR and initialize CA stuff


# openssl ca -config ca.selfsign.cnf -out cacert.pem -batch \
  -keyfile ca.key -selfsign -infiles cacert.pkcs10</description>
    </item>
</rdf:RDF>
