SunScreen v3.1 to v3.0b communications
From: sean@boran.comDate: 10/02/01
- Previous message: Chris Ricker: "Re: IPSEC on Solaris 8"
- Next in thread: Valerie Anne Bubb: "Re: SunScreen v3.1 to v3.0b communications"
- Reply: Valerie Anne Bubb: "Re: SunScreen v3.1 to v3.0b communications"
- Reply: Sean Boran: "RE: SunScreen v3.1 to v3.0b communications"
- Reply: Valerie Anne Bubb: "RE: SunScreen v3.1 to v3.0b communications"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: sean@boran.com To: <focus-sun@securityfocus.com> Subject: SunScreen v3.1 to v3.0b communications Date: Tue, 2 Oct 2001 12:33:26 +0200 Message-ID: <002501c14b2d$ab606f80$0a1111b0@swissptt.ch>
Hi,
I'm trying to get a (new) Sunscreen EFS 3.1 working with an existing
administration station which manages a group of Sunscreen 3.0b. They are
internation versions (weak keys).
The problem is SKIP (as usual... :-).
After a bit of digging, I noticed that the v3.0b key sizes are 512bit
and the v3.1 keys are 1024 bit.
Ss_install doesn't allow me to specify key sizes, has anyone found a way
of making these beasts talk to each other?
I tried to manually create and use 512bit keys using the procedure below
but now luck..
I also tried to stop SKIP altogether (lots of acrobatics). Sunscreen
doesn't like this at all. A pity because SSH is enough (for me) when you
have a dedicated management network..
Any help would be appreciated..
Sean Boran
Creating new sunscreen keys:
a) Sunscreen:
List current keys:
skiplocal -l
Delete current keys:
skiplocal -r -s 0
Create new one:
skiplocal -k -m 512
Print out command for other side:
skiplocal -x
Add local and remote certs to Sunscreen engine:
ssadm edit Mypolicy
edit> list certificate
edit> add certificate "admin-group" GROUP "remote"
edit> add certificate "remote" SINGLE NSID 8 MKID
"0x4fd3a1eec3a168e1lotsofcrap"
edit> add certificate "MyScreen.admin" SINGLE NSID 8 MKID
"0x9c6e6b0822b590otsofcrap"
edit> save
ssadm activate Mypolicy
skipd_restart
b) Admin station:
Delete ACL entry to screen:
skiphost -i le0 -d MyScreenIP
Add new entry according to "skiplocal -x" above.
Save skip settings and restart skip:
skipif -i all -s
skipd_restart
- Previous message: Chris Ricker: "Re: IPSEC on Solaris 8"
- Next in thread: Valerie Anne Bubb: "Re: SunScreen v3.1 to v3.0b communications"
- Reply: Valerie Anne Bubb: "Re: SunScreen v3.1 to v3.0b communications"
- Reply: Sean Boran: "RE: SunScreen v3.1 to v3.0b communications"
- Reply: Valerie Anne Bubb: "RE: SunScreen v3.1 to v3.0b communications"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|