Yabdro / Applied-Security-CA-Project

0 stars 0 forks source link

Applied-Security-CA-Project

Setup

Network info

Network Addresses:

Credentials

The following format is used: username:password.

Client machine (Clark) user accounts:

Webserver machine (Wynona) user accounts:

Database and CA machine (Dakota) user accounts:

Backup machine (Benedict) user accounts:

Gateway machine (Grace) user accounts:

Config Info

The configuration files for both Wynona's and Dakota's webserver are located in /etc/apache2/sites-availabe on the respective machine. The Web directories are in /var/www/imovies and /var/www/auth_manager respectively. A copy of these two directories and of both config files can be found in this repository.

General

To reach the Webserver from the client machine, just open a browser and type https://imovies.asl.com or https://Wynona. The only CA admin out of all the user is Patrick Schaller, so if you want to access the CA admin interface you need to use his account (and certificate-based authentication). We reccomend using Chrome as we have had problems importing our generated client-certificates into Firefox. If you want to use Firefox, we have found that importing a certificate into Chrome, then exporting it and importing that into Firefox will actually work.Other users (except for Lukas Bruegger) do not have a certificate installed already, so for the first login you will need to use credentials. To import the certificate you need to do it from inside the browsers settings, not by opening the .pfx file.

To access the internal network, you need to SSH from the client to the gateway using the alex account. When logged in as alex you can use ssh sysadmin@Grace to connect to it. Once inside the internal network, SSH access should work without password authentication from Grace to every machine.