IPSec using racoon w/ kerberos authentication


 
Thread Tools Search this Thread
Operating Systems Linux IPSec using racoon w/ kerberos authentication
# 1  
Old 10-21-2008
IPSec using racoon w/ kerberos authentication

Hi,

Anyone can point me a good link to setup IPSec using racoon IKE which uses gssapi_krb authentication method?

I have a debain linux box and Windows 2003R2 system, and I want them to communicate using IPSec.

Thanks,
Emily.
Login or Register to Ask a Question

Previous Thread | Next Thread

7 More Discussions You Might Find Interesting

1. Shell Programming and Scripting

PERL and Kerberos authentication

I am installing Authen::Krb5::Easy and during make test I am getting the follwing error : kinit not ok 2 error was: could not get initial credentials: Cannot contact any KDC for requested realm we are stroring krb5.conf in diff location ( not in /etc/krb5.conf) , but, PERL is... (1 Reply)
Discussion started by: talashil
1 Replies

2. Shell Programming and Scripting

How to automatically store/cache password for kerberos authentication

Hi All, I am currently writing script to get the details for lot of hosts from jump server. Means each and every time it will ssh to the host and get the information. To achieve that I need to automatically accept the password from Jump server to that main hosts. We are using kerberos password... (6 Replies)
Discussion started by: kamauv234
6 Replies

3. UNIX for Dummies Questions & Answers

Kerberos Authentication error

Hi , I am trying to authenticate my id on client server with Kerberos and receiving below error kinit rpagadala@BDC.soft.net kinit: Cannot contact any KDC for realm 'BDC.soft.net' while getting initial credentials Please find krb5.conf on the client server configuration which is... (1 Reply)
Discussion started by: Tomlight
1 Replies

4. AIX

SSH and kerberos authentication problem AIX 5.3

I've configured an AIX 5.3 client to use our Windows AD for user authentication via Kerberos. When I try to ssh to the server using the AD credentials, I eventually get access but not after getting prompted for a password 3 times (which doesn't work) followed by an accepted login on the 4th... (3 Replies)
Discussion started by: jmroderick
3 Replies

5. Red Hat

PAM configuration: Kerberos authentication and NIS authorization problem

Hi, I've configured two linux boxes to authenticate against Windows Active Directory using Kerberos while retrieving authorization data (uids, gids ,,,)from NIS. The problem I ran into with my PAM configuration is that all authentication attempts succeed in order.i.e. if someone tried his... (0 Replies)
Discussion started by: geek.ksa
0 Replies

6. Programming

Kerberos Authentication c/c++

I am in the process of developing a application that needs to be able to authenticate users details with a kerberos server, which is proving to be rather difficult. There seems to be a lack of good information on how to do this using the MIT kerberos api. Can anyone point me in the right... (0 Replies)
Discussion started by: mshindo
0 Replies

7. UNIX for Dummies Questions & Answers

Kerberos Authentication from Application

Hi, We've configured Kerberos to authenticate AIX 5.3 users with Active Directory and I now have to port an application written in C to the new security model. Currently, our users can login as normal and running a "klist" command reveals that they have been successfully granted a ticket. ... (2 Replies)
Discussion started by: phykell
2 Replies
Login or Register to Ask a Question
ipsec_config(1M)														  ipsec_config(1M)

NAME
ipsec_config - add, delete, export, and show HP-UX IPSec configuration objects in the HP-UX IPSec configuration database SYNOPSIS
[operation [object_type]] DESCRIPTION
The command adds, deletes, exports, and shows HP-UX IPSec configuration objects in the HP-UX IPSec configuration database, If HP-UX IPSec is active and running, also updates the HP-UX runtime IPSec policy database and runtime IKE information (IKE policies and authentication records). You must be superuser to run The utility can operate in command-line mode or batch mode. In command-line mode, reads all input from the command line. In batch mode, reads add and delete operations from a file. Batch mode allows administrators to add and delete multiple configuration objects in one operation. HP-UX IPSec processes the operations in a batch file as a group. Batch mode is useful if you are adding or deleting configura- tion records that may affect other records. HP recommends that you use a batch file to add configuration information. A batch file provides a permanent record of the configuration data and can be used to re-create the configuration database. Separate command arguments using whitespace (blanks, tabs or newlines). Use a backslash line continuation character to continue command input on subsequent lines. Operations and Object Types The command supports the following operations: See ipsec_config_add(1M) for more information. See ipsec_config_batch(1M) for more information. See ipsec_config_delete(1M) for more information. See ipsec_config_export(1M) for more information. See ipsec_config_show(1M) for more information. object_type can be one of the following: Authentication records, which specify Internet Key Exchange (IKE) versions, authentication methods, identity information and preshared keys. Bypass addresses. security certificate for a Certificate Authority (used for IKE authentication with RSA signatures). Certificate Revocation List (CRL). A CRL contains a list of revoked X.509 security certificates. If you have a CRL, HP-UX IPSec check it during the IKE authentication process to verify that the remote system's security certificate is valid (not revoked). Certificate Signing Request (CSR), which the HP-UX IPSec administrator can submit to a Certificate Authority (CA) to request a signed X.509 security certificate. Host IPsec policies, which specify HP-UX IPSec behavior for processing IP packets when the local system is an end host. IKE version 1 (IKEv1) policies. IKE version 2 (IKEv2) policies. security certificate for the local system (used for IKE authentication with RSA signatures). Start-up options. Tunnel IPsec policies, which specify IPsec tunnel transform parameters. Configuring Objects In most HP-UX IPSec topologies, you must configure the following objects: o Host IPsec policies o Authentication records (IKE ID information and preshared keys) To establish IPsec security, you must also have an IKE version 1 (IKEv1) or IKE version 2 (IKEv2) policy. The HP-UX IPSec product installs a default IKEv1 policy and a default IKEv2 policy. You can use these default policies without modifications in many topologies. HP recommends that you use the following procedure to configure HP-UX IPSec: 1. Create a batch file to configure IPsec policies and authentication records. An IKEv1 or IKEv2 policy is also required, but in most cases you can use the default IKEv1 or IKEv2 installed with the product. If you want to configure host-to-host IPsec poli- cies and use IKE with preshared keys for IKE authentication, create a batch file to contain the following statements: See the command subsection in ipsec_config_add(1M) for syntax and usage information. If you are using HP-UX IPSec with certificates (RSA signatures) for IKE authentication, you must also use the following com- mands to configure certificates: You must enter the above commands at the command-line prompt. (You cannot specify them in an batch file). The command creates a certificate signing request (CSR). As an alternative, you can use a utility provided by the certificate vendor to create the CSR. 2. Test the syntax of your batch file by entering the following command: The option verifies the syntax without adding objects to the database. 3. If the syntax is correct, add the configuration information to the configuration database by entering the following command: 4. Start and verify HP-UX IPSec. Use the following command to start HP-UX IPSec: Generate network traffic that uses IPsec. Use the following command to verify operation: Verify that HP-UX IPSec has created Security Associations (SAs) with the appropriate systems. 5. Use the command to configure HP-UX IPSec to automatically start at system boot-up time. ipsec_config Help The displays help and usage information for the HP-UX IPSec operations. Use the following syntax to access help: [operation [option_type]] EXAMPLES
You have two systems, Apple and Banana Apple and Banana are not multihomed. You want to secure all telnet packets between the two systems using IPsec ESP with AES, authenticated with SHA-1. The IKE version is IKEv1. This is a private network, and you will allow all other packets to pass in clear text. You use the default IKEv1 policy. On Apple, you configure: o Two host IPsec policies o One authentication record The first host IPsec policy, telnetAB, secures outbound telnet connections (Apple is the telnet client). You do not need to specify the source argument, since it will default to any IP address and any port, and the telnet client port number is dynamically allocated. The second policy, telnetBA, secures inbound telnet connections (Apple is the telnet server). The authentication record specifies the preshared key value used with (Banana): The configuration on Banana is the mirror image of the configuration on Apple: AUTHOR
was developed by HP. FILES
configuration database. default profile file. SEE ALSO
ipsec_admin(1M), ipsec_config_add(1M), ipsec_config_batch(1M), ipsec_config_delete(1M), ipsec_config_export(1M), ipsec_config_show(1M), ipsec_migrate(1M), ipsec_policy(1M), ipsec_report(1M). HP-UX IPSec Software Required ipsec_config(1M)