Bài đăng

CERTIFICATE VALIDATION with CRL, OCSP and OCSP tapling

Hình ảnh
Certificate Revocation Mỗi một certificate được tạo ra đều có một khoảng thời gian hiệu lực ( validity period  ) nhất định và thường từ 1 hoặc 2 năm. Khi vượt ra khỏi khoảng thời gian này thì nó bị hết hạn và không còn giá trị nữa. Thông tin này được chứa trong bản thân certificate (giá trị  valid from  và  valid to   ) và cần được kiểm tra trước khi quyết định có nên tin dùng nó hay không. Tuy nhiên, có những trường hợp mà một certificate cũng cần bị thu hồi ( revoke ) dù rằng thời gian hiệu lực vẫn còn như: Người sở hữu certificate không còn làm trong tổ chức nữa. CA phát hiện ra là đã cấp phát sai certificate. Sự cố liên quan tới các CA  Comodo , DigiNotar  xảy ra gần đây là một ví dụ. Private key bị lộ hoặc thiết bị chứa private key bị mất hoặc bị đánh cắp. Công việc thu hồi certificate này được gọi là certificate revocation và do CA thực hiện. Có 2 trạng thái revocation được quy định trong  RFC 3280  là: Revoked : một...

Setup And Configure OpenVPN Server On CentOS 6.5

Introduction OpenVPN  is a robust and highly flexible tunneling application that uses all of the encryption, authentication, and certification features of the OpenSSL library to securely tunnel IP networks over a single TCP/UDP port. OpenVPN is developed by James Yonan of OpenVPN Technologies. In this brief guide, let us setup OpenVPN server on CentOS 6.5, and connect from a remote client. For the purpose of this tutorial, I use two systems running with CentOS 6.5, one acts as VPN server and other one acts as VPN client. Part One – VPN Server Side Configuration Here, I use CentOS 6.5 as VPN server, and it’s actual IP address is 192.168.1.2/24. Prerequisites OpenVPN and it’s dependencies are not available in the CentOS default repositories. So, we should install the  “EPEL”  repository in order to install OpenVPN and its dependencies. To enable EPEL repository On CentOS, refer the following link. Install EPEL Repository On CentOS / RHEL / Scientific Linux ...

Using HAproxy in multi core environments

HAproxy  is a great load balancing solution that we use at  Instela . We use HAProxy in a 8-Cores bare metal machine and we also use it to offload SSL encryption. Although HAproxy is very effective solution in terms of CPU usage, SSL offloading obviously needs more CPU power, thus, using only one core could be easily a bottleneck. Apart from this, also we did not want to waste other cores and we decided to activate  not recommended multi core support. The configuration is pretty straightforward. At the  global  section of  haproxy.cfg , we put these directives: nbproc 15 cpu - map 1 1 cpu - map 2 2 cpu - map 3 3 cpu - map 4 4 cpu - map 5 5 cpu - map 6 6 cpu - map 7 7 cpu - map 8 8 cpu - map 9 9 cpu - map 10 10 cpu - map 11 11 cpu - map 12 12 cpu - map 13 13 cpu - map 14 14 cpu - map 15 1...