Escolar Documentos
Profissional Documentos
Cultura Documentos
/LQX[ DUWLJRVFDWHJRULD,QGH[SKS"FRGLJR
6HJXUDQoD DUWLJRVYHU6XE&DWHJRULDSKS"FRGLJR
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
3RU&DUORV(GXDUGR0DFLHO5RGULJXHVHP >+LWV@
'HQXQFLH GHQXQFLHLQGH[SKS )DYRULWRV DGG%RRNPDUNSKS"
WLSR DUWLJR FRGLJR ,QGLFDU IRUP,QGLFDUSKS"WLSR DUWLJR FRGLJR
,PSUHVVRUD DUWLJRVLPSUHVVRUDSKS"FRGLJR
CONFIGURAÇÃO DOS SERVIDORES E DO OPENVPN
1HVWHDUWLJRHVWRXH[SOLFDQGRRSDVVRDSDVVRVREUHFRPRLPSODQWDUXPDVPNXWLOL]DQGR
OpenVPNFRPVHUYLGRUHVCentOS 6RXRed HatH&OLHQWHV:LQGRZV
(VWHFHQiULRpPXLWRXVDGRHPHPSUHVDVTXHSRVVXHPXPDPDWUL]HWHPFRQVXOWRUHVH[WHUQRV
TXHSUHFLVDPWHUDFHVVRDRVVHUYLGRUHVGHGDGRVGDPDWUL]
3ULPHLURSDVVRYDPRVFRQILJXUDURVHUYLGRU2SHQ931TXHIDUiDDXWHQWLFDomRGRVXVXiULRV
,QVWDOHRVSDFRWHV
)DoD'RZQORDGGRVSDFRWHV
$ wgetKWWSRSHQYSQQHWUHOHDVHRSHQYSQWDUJ] KWWSRSHQYSQQHWUHOHDVHRSHQYSQ
WDUJ]
$ wgetKWWSRSHQYSQQHWUHOHDVHO]RUIVUFUSP KWWSRSHQYSQQHWUHOHDVHO]R
UIVUFUSP
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV>$UWLJR@
$ wget ftp://ftp.muug.mb.ca/mirror/fedora/epel/5/x86_64/pkcs11
helper1.072.el5.1.i386.rpm
$ wget ftp://ftp.muug.mb.ca/mirror/fedora/epel/5/x86_64/pkcs11
helperdevel1.072.el5.1.i386.rpm
,QVWDOHRVSDFRWHVEDL[DGRV
1DVHTXrQFLDFULHXPGLUHWyULRFKDPDGRRSHQYSQGHQWURGR/etc
# mkdir /etc/openvpn
(QWUHGHQWURGRGLUHWyULR/etc/openvpn
# cd /etc/openvpn
&RSLHRGLUHWyULR/usr/share/doc/openvpn2.1.3/easyrsa/2.0/SDUDGHQWURGR/etc/openvpn
# cp r /usr/share/doc/openvpn2.1.3/easyrsa/2.0/
'HQWURGRGLUHWyULRetc/openvpn/2.0FRQWpPRVVFULSWVQHFHVViULRVSDUDFRQILJXUDomRGD931
KWWSLPJYLYDROLQX[FRPEULPDJHQVDUWLJRVFRPXQLGDGH,7(0BSQJ
# cd /etc/openvpn/2.0
# vim vars
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV>$UWLJR@
7URTXHRVSDUkPHWURVDEDL[RSHORVGHVXDHPSUHVDHVDOYHRDUTXLYR
KWWSLPJYLYDROLQX[FRPEULPDJHQVDUWLJRVFRPXQLGDGH,7(0BSQJ
$JRUDYDPRVFDUUHJDUHVWHVDUTXLYRVQDPHPyULDSDUDTXHRVPHVPRVVHMDPFRORFDGRV
FRPYDULiYHLVGHDPELHQWH
# source ./vars
9DPRVH[HFXWDURVFULSWcleanallSDUDTXHVHMDOLPSRWRGDVDVFKDYHVHQmRKDMDFRQIOLWRGH
YDULiYHLV
# ./cleanall
$JRUDYDPRVFRPHoDUDFULDUDVDXWRULGDGHVFHUWLILFDGRUDVHRVFHUWLILFDGRV
#./buildca
2PHVPRLUiWUD]HURVYDORUHVSDGU}HVDWpPHVPRSRUTXHHGLWDPRVRDUTXLYRvarsDSHQDV
FRQILPHSUHVVLRQDQGRENTERSDUDFRQFOXLUDFULDomRGDDXWRULGDGHFHUWLILFDGRUD
$SDUWLUGHDJRUDIRLFULDGRXPGLUHWyULRFKDPDGR.H\VRQGHFRQWpPRVFHUWLILFDGRVGD &$
2EVeLPSRUWDQWHTXHHVWHFHUWLILFDGRH[LVWDWDQWRQRVHUYLGRUFRPRQRFOLHQWH
9DPRVJHUDURVFHUWLILFDGRVGRVHUYLGRU
#./buildkeyserver Matriz
2EV0DWUL]pRQRPHGRPHXVHUYHU
(XQmRFRORFRDWULEXWRVH[WUDVGHVHJXUDQoD
&RQILUPHRVGDGRV
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV>$UWLJR@
$SyVDFULDomRGRFHUWLILFDGRYHULILTXHQRGLUHWyULR.H\VTXHDJRUDH[LVWHRFHUWLILFDGR0DWUL]
DFKDYHGHDFHVVRHDUHTXLVLomRGRFHUWLILFDGR
PDWUL]NH\
PDWUL]FVU
PDWUL]FUW
$JRUDYDPRVJHUDUDVFKDYHVGRVPHXVFOLHQWHVRXFRQVXOWRUHVH[WHUQRVYRXFKDPDUGH
FRQVXOWRU
#./buildkey consultor1
&RQILUPHRVGDGRV QmRXWLOL]RVHQKDDVVLPQXPSULPHLURPRPHQWRSRGHUiYDOLGDUVHVXDV
FKDYHVHVWmRIXQFLRQDQGR
FRQVXOWRUNH\
FRQVXOWRUFVU
FRQVXOWRUFUW
(SRUILPYDPRVFULDURFHUWLILFDGRDiffie hellman(VWHFHUWLILFDGRpPXLWRLPSRUWDQWHSRLVR
PHVPRJDUDQWHTXHWRGDWURFDGHFKDYHVVHUiIHLWRFRPWRGDVHJXUDQoD
# ./builddh
9HULILTXHQRGLUHWyULRV.H\VTXHDVFKDYHVIRUDPFULDGDVDVFKDYHVGR&$0$75,=
&2168/725H'+
&DVRQmRDFRQWHFHXYHULILTXHVHQmRSXORXQHQKXPSDVVR
9DPRVFULDUXPOLQNVLPEyOLFRTXHYDLDSRQWDUSDUDRGLUHWyULR.H\V
# ln s /2.0/keys keys
,VWRYDLIDFLOLWDURDFHVVRDRGLUHWyULR
2SUy[LPRSDVVRVHUiFRQILJXUDUDPDWUL]SDUDID]HUDDXWHQWLFDomRGRVXVXiULRV9DPRVFULDU
XPDUTXLYRFKDPDGRPDWUL]FRQIGHQWURGRGLUHWyULR/etc/openvpn/
# touch matriz.conf
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV>$UWLJR@
KWWSLPJYLYDROLQX[FRPEULPDJHQVDUWLJRVFRPXQLGDGH,7(0BSQJ
$JRUDVyIDOWDUHLQLFLDURVHUYLoR931
# /etc/init.d/openvpn restart
&DVRH[LVWDDOJXPSUREOHPDSRUIDYRUYHULILTXHHPORJ
9DPRVFRQILJXUDURVFOLHQWHTXHVHUiRQRVVRFRQVXOWRU
1HVWHDUWLJRHVWRXXWLOL]DQGRROpenVPNPortableHVWHDSOLFDWLYRSHUPLWHTXHRPHVPRVHMD
XWLOL]DGRHPXPSHQGULYHHVHMDH[HFXWDGRHPTXDOTXHUFRPSXWDGRUTXHSRVVXD:LQGRZV
23DFRWHFRQWpPDOJXPDVSDVWDV
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV>$UWLJR@
KWWSLPJYLYDROLQX[FRPEULPDJHQVDUWLJRVFRPXQLGDGH,7(0BSQJ
1RDUTXLYR2SHQ9313RUWDEOHLQLWHPRVDVVHJXLQWHVFRQILJXUDo}HV
KWWSLPJYLYDROLQX[FRPEULPDJHQVDUWLJRVFRPXQLGDGH,7(0BSQJ
2EVHUYDomR1HVWHDUTXLYRSUHFLVDVHUWURFDGRRSDUkPHWURAutoConnectSDUDRQRPHGD
FKDYHFULDGDQRFDVRGRH[HPSORHVWRXXWLOL]DQGR&RQVXOWRU
'HQWURGRGLUHWyULRdataH[LVWHXPGLUHWyULRconfigTXHFRQWpPDVFKDYHVHRDUTXLYRFRPD
H[WHQVmRRYSQRVPHVPRVGHYHPILFDUGDVHJXLQWHIRUPD
KWWSLPJYLYDROLQX[FRPEULPDJHQVDUWLJRVFRPXQLGDGH,7(0BSQJ
$FLPDFRQWpPDVFKDYHVFULDGDVQRVHUYLGRUTXHIRUDPFRSLDGDVSDUDGHQWURGRGLUHWyULR
configHMXQWRFRPDVFKDYHVpFRQWLGRRDUTXLYRFRQVXOWRURYSQ
1HVWHDUTXLYRH[LWHPRVSDUkPHWURVGHFRQILJXUDomRGRFOLHQWHSDUDFRQH[mRFRPRVHUYLGRU2V
SDUkPHWURVGHYHPILFDUGDVHJXLQWHIRUPD
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV>$UWLJR@
KWWSLPJYLYDROLQX[FRPEULPDJHQVDUWLJRVFRPXQLGDGH,7(0BSQJ
$SyVRWpUPLQRGDVFRQILJXUDo}HVGRFOLHQWHH[HFXWHRDUTXLYROpenVPNPortable.exe
2PHVPRIDUiDFRQH[mRDXWRPiWLFDFRPR6HUYLGRU931
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV>$UWLJR@
&RPRGLFDH[LVWHPDOJXPDVREVHUYDo}HV
&DVRWHQKDPG~YLGDVVHJXHRPHXHPDLOFDGXURGULJXHV>DW@KRWPDLOFRP
3iJLQDVGRDUWLJR
&RQILJXUDomRGRVVHUYLGRUHVHGR2SHQ931
2XWURVDUWLJRVGHVWHDXWRU
1HQKXPDUWLJRHQFRQWUDGR
/HLWXUDUHFRPHQGDGD
5HFXSHUDUDVHQKDGHURRWLQLFLDQGRDWUDYpVGRLQLW ELQEDVKHDOWHUDQGRRDUTXLYR
HWFVKDGRZ DUWLJR5HFXSHUDUDVHQKDGHURRWLQLFLDQGRDWUDYHVGRLQLW ELQEDVKHDOWHUDQGR
RDUTXLYRHWFVKDGRZ
$QiOLVHGH0DOZDUHHP)RUHQVH&RPSXWDFLRQDO DUWLJR$QDOLVHGH0DOZDUHHP)RUHQVH
&RPSXWDFLRQDO
8VDQGRHLQVWDODQGRR1HVVXVQR/LQX[ DUWLJR8VDQGRHLQVWDODQGRR1HVVXVQR/LQX[
*HUHQFLDUHFRQILJXUDULQHWGHVHUYLoRVUHODFLRQDGRV DUWLJR*HUHQFLDUHFRQILJXUDULQHWGH
VHUYLFRVUHODFLRQDGRV
&RPHQWiULRV
&DUDPEDPXLWRVKRZDWHPSRVWRWHQWDQGRLPSOHPHQWDUXPVHUYLGRUFRPHVWUXWXUDSDUHFLGD
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV>$UWLJR@
YRXDQDOLVDUFRPFDOPDRWXWRULDOHSRUHPSUiWLFDHPEUHYH
9DOHX
%RPDUWLJRSDUDEpQV
2Oi&ORFNZRUNOLQX[
2EULJDGRSHODFRQWULEXLomRHVWHFHQiULRMiWHQKRIXQFLRQDQGRHPDOJXQVFOLHQWHVFDVRSUHFLVH
GHDMXGDVyHQWUDUHPFRQWDWR
$Eo
&DUORV5RGULJXHV
>@&RPHQWiULRHQYLDGRSRUFORFNZRUNOLQX[HPK
&DUDPEDPXLWRVKRZDWHPSRVWRWHQWDQGRLPSOHPHQWDUXPVHUYLGRUFRPHVWUXWXUD
SDUHFLGDYRXDQDOLVDUFRPFDOPDRWXWRULDOHSRUHPSUiWLFDHPEUHYH
9DOHX
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV>$UWLJR@
2Oi5RGULJR
2EULJDGRSHODFRQWULEXLomRFDVRSUHFLVHGHDMXGDSDUDLPSOHPHQWDUVyHQWUDUHPFRQWDWR
$Eo
&DUORV5RGULJXHV
FDGXURGULJXHV#KRWPDLOFRP
>@&RPHQWiULRHQYLDGRSRUURGULJRNL\RVKLHPK
%RPDUWLJRSDUDEpQV
0XLWRERPRDUWLJRXWLOL]DPRV931QDHPSUHVDSRUpPQDSODWDIRUPD:LQGRZV
(VWDUHLUHSDVVDQGRDLQIRUPDomRSDUDQRVVR$GP5HGHVSDUDDWULEXLUPRVHPXPSURMHWRGH
PHOKRULDV
2EULJDGR
$Eo
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV>$UWLJR@
EDFDQDRDUWLJRPDVGHYHULDWHUFRORFDGRRVDTUXLYRVSDUDGRZQORDGHSRGHUFRSLDUFRORFDU
HPLPDJHPIRLPDQFDGD
2NPXLWRREULJDGR
&DUORV5RGULJXHV
>@&RPHQWiULRHQYLDGRSRUFDGXURGULJXHVHPK2Oi5RGULJR
2EULJDGRSHODFRQWULEXLomRFDVRSUHFLVHGHDMXGDSDUDLPSOHPHQWDUVyHQWUDUHP
FRQWDWR$Eo&DUORV5RGULJXHVFDGXURGULJXHV#KRWPDLOFRP
>@&RPHQWiULRHQYLDGRSRUURGULJRNL\RVKLHPK%RPDUWLJR
SDUDEpQV
$PLJRERDQRLWH
2EULJDGRSHORFRPHQWiULRSRUpPRVDUWLJRVSDUD'RZQORDGMiHVWmRFRPRVOLQNV
GLVSRQLELOL]DGRVSDUDGRZQORDGVRDSOLFDWLYRGRZLQGRZVSRGHVHUHQFRQWUDWRQD
ZZZRSHQYSQQHW KWWSZZZRSHQYSQQHW
DEo
&DUORV5RGULJXHV
>@&RPHQWiULRHQYLDGRSRU-26(5)HPKEDFDQDRDUWLJRPDV
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV>$UWLJR@
GHYHULDWHUFRORFDGRRVDTUXLYRVSDUDGRZQORDGHSRGHUFRSLDUFRORFDUHPLPDJHP
IRLPDQFDGD
3DUDEpQVSHORDUWLJR2EULJDGRSRUHVFODUHFHUDVPLQKDVG~YLGDV
$EUDoR
0XLWRERP
$MXGRXEDVWDQWH
ERDQRLWHVHLTXHRWRSLFRpXPSRXFRDQWLJRPDVJRVWDULDPXLWRGHVDEHUVHHVWDV
FRQILJXUDoRHVVHDSOLFDPWEHPDXPVHUYLGRUFHQWRVVDPEDFRPRGRPLQLR2EULJDGR
(QYLDU
$PDLRUFRPXQLGDGH*18/LQX[GD$PpULFD/DWLQD$UWLJRVGLFDVWXWRULDLVIyUXPVFULSWVHPXLWR
PDLV,GHDOSDUDTXHPEXVFDDXWRDMXGD
)$43HUJXQWDVIUHTXHQWHV IDTSKS
(VWDWtVWLFDVGRVLWH HVWDWLVWLFDVSKS
(TXLSHGHPRGHUDGRUHV HTXLSH
0HPEURVGDFRPXQLGDGH PHPEURV
$QXQFLH DQXQFLH
&RQWDWR IDOHFRP
3ROtWLFDGHSULYDFLGDGH SULYDFLGDGH
4XHPVRPRV TXHPVRPRV
7HUPRVGHXVR WHUPRVGHXVR
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV
931HQWUHVHUYLGRUHV&HQW26H:LQGRZV>$UWLJR@
6LWHKRVSHGDGRSRU
YHU%DQQHUSKS"FRGLJR
KWWSZZZYLYDROLQX[FRPEUDUWLJR931HQWUHVHUYLGRUHV&HQW26H:LQGRZV