Closed Werewolfman77 closed 6 months ago
Managed to add the station by manually creating .ssh/authorized_keys on the station and editing it and adding the pub key of the admin
And enrolling worked
Two more question though...
1 ) any compiled version for the windows driver? as there is no manual for doing this 2) when inserting a usb with file it detects the usb and analyzez the files ....but it keeps saying analyzing..it did not finish for long time (only 10 files for testing) ...when signing a usb key and inaerting it and detects a signed key but files are not copied to it...only .krp files...any explanation ?
root@Keysas-USB:/usr/share/keysas/rules# journalctl -fu keysas-in.service Apr 27 21:37:31 Keysas-USB systemd[1]: Started keysas-in.service - keysas-in daemon. Apr 27 21:37:31 Keysas-USB (eysas-in)[227864]: keysas-in.service: ProtectHostname=yes is configured, but the kernel does not support UTS namespaces, ignoring namespace setup. Apr 27 21:37:31 Keysas-USB keysas-in[227864]: 2024-04-27T18:37:31.181Z INFO [keysas_in::sandbox] Keysas-in is now fully sandboxed using Landlock ! Apr 27 21:37:31 Keysas-USB keysas-in[227864]: 2024-04-27T18:37:31.181Z INFO [keysas_in] Landlock sandbox activated. Apr 27 21:37:31 Keysas-USB keysas-in[227864]: 2024-04-27T18:37:31.181Z INFO [keysas_in] Seccomp sandbox activated. Apr 27 21:37:31 Keysas-USB keysas-in[227864]: 2024-04-27T18:37:31.181Z INFO [keysas_in] Keysas-in started :) Apr 27 21:37:31 Keysas-USB keysas-in[227864]: 2024-04-27T18:37:31.181Z INFO [keysas_in] Running configuration is: Apr 27 21:37:31 Keysas-USB keysas-in[227864]: 2024-04-27T18:37:31.181Z INFO [keysas_in] - Abstract socket: socket_in Apr 27 21:37:31 Keysas-USB keysas-in[227864]: 2024-04-27T18:37:31.181Z INFO [keysas_in] - sas_in: /var/local/in/ Apr 27 21:37:31 Keysas-USB keysas-in[227864]: 2024-04-27T18:37:31.184Z INFO [keysas_in] Socket for Keysas-transit created.
root@Keysas-USB:/usr/share/keysas/rules# journalctl -fu keysas-transit.service Apr 27 21:37:30 Keysas-USB systemd[1]: Stopped keysas-transit.service - keysas-transit daemon. Apr 27 21:37:30 Keysas-USB systemd[1]: keysas-transit.service: Consumed 1.427s CPU time. Apr 27 21:37:31 Keysas-USB systemd[1]: Started keysas-transit.service - keysas-transit daemon. Apr 27 21:37:31 Keysas-USB keysas-transit[227866]: 2024-04-27T18:37:31.464Z INFO [keysas_transit::sandbox] Keysas-transit is now fully sandboxed using Landlock ! Apr 27 21:37:31 Keysas-USB keysas-transit[227866]: 2024-04-27T18:37:31.464Z INFO [keysas_transit] Landlock sandbox activated. Apr 27 21:37:31 Keysas-USB keysas-transit[227866]: 2024-04-27T18:37:31.466Z INFO [keysas_transit] Seccomp sandbox activated. Apr 27 21:37:31 Keysas-USB keysas-transit[227866]: 2024-04-27T18:37:31.614Z INFO [keysas_transit] Version: ClamAV 1.0.3/27257/Fri Apr 26 11:25:03 2024 Apr 27 21:37:33 Keysas-USB keysas-transit[227866]: 2024-04-27T18:37:33.551Z INFO [keysas_transit] Yara compiler initialized. Apr 27 21:37:33 Keysas-USB keysas-transit[227866]: 2024-04-27T18:37:33.552Z INFO [keysas_transit] Connected to Keysas-in socket. Apr 27 21:37:33 Keysas-USB keysas-transit[227866]: 2024-04-27T18:37:33.552Z INFO [keysas_transit] Socket for Keysas-out created.
root@Keysas-USB:/usr/share/keysas/rules# journalctl -fu keysas-out.service Apr 27 21:37:32 Keysas-USB keysas-out[227867]: 2024-04-27T18:37:32.172Z ERROR [keysas_out] Failed to open abstract socket with keysas-transit Connection refused (os error 111) Apr 27 21:37:32 Keysas-USB systemd[1]: keysas-out.service: Main process exited, code=killed, status=31/SYS Apr 27 21:37:32 Keysas-USB systemd[1]: keysas-out.service: Failed with result 'signal'. Apr 27 21:37:34 Keysas-USB systemd[1]: keysas-out.service: Scheduled restart job, restart counter is at 1. Apr 27 21:37:34 Keysas-USB systemd[1]: Stopped keysas-out.service - keysas-out daemon. Apr 27 21:37:34 Keysas-USB systemd[1]: Started keysas-out.service - keysas-out daemon. Apr 27 21:37:34 Keysas-USB keysas-out[227870]: 2024-04-27T18:37:34.376Z INFO [keysas_out::sandbox] Keysas-out is now fully sandboxed using Landlock ! Apr 27 21:37:34 Keysas-USB keysas-out[227870]: 2024-04-27T18:37:34.376Z INFO [keysas_out] Landlock sandbox activated. Apr 27 21:37:34 Keysas-USB keysas-out[227870]: 2024-04-27T18:37:34.377Z INFO [keysas_out] Seccomp sandbox activated. Apr 27 21:37:34 Keysas-USB keysas-out[227870]: 2024-04-27T18:37:34.984Z INFO [keysas_out] Connected to keysas-transit socket.
It is working now I just had to insert the signed key after the non signed key
But the front end keeps giving the msg analyzing dont remove the flash drive!! Even when the files are copied to signed drive
That leaves to 1st question...any compiled driver for usb? Or compiling instructions??
Thanx for rhe great project
Hi, Glad that you finally made it work ! Yes, the AppWizard-en.vue is outdated and needs to be updated, I'll patch it for the next release. To be honest, I think you're the first non-French speaking person to use it :) ! Regarding the windows driver, you need to buy an official certificate to sign the driver (unless your Windows is in dev mode). Actually, you only need to load the keysas-firewall code into Microsoft Visual Studio 2022 with SDK and WDK version 10.0.22621.0 add your certificate and click to build the project.
Well...actually i am not english speaking either...i mean not my first language :)
As for french i had to use google translate to be able to read other issues comments to be able yo solve my issues...and it paid
Anyway...thanx for the nice project...and i will try to build the driver and see how it goes
You're welcome, I'm glad you find this project useful ! BTW, I've just pushed a first update of AppWizard-en.vue, feel free to review : https://github.com/r3dlight/keysas/blob/Develop/keysas-frontend/src/components/AppWizard-en.vue
building front-end resulting in French interface when i tried modifing the locale in main.js and also app.vue to be english , there were multiple error compiling 'AppWizard-en.vue'
for example:
The operating system is based on a hardened GNU/Linux Debian 11 (codename: Bullseye). DHCP on on by default so you may want to check your network router to get back the IP address assigned to your Keysas at boot.**__** at last it worked and the GUI was english but i can't add the station to the admin..it gives Error: cannot connect to the keysas station i noted that: keysas.service - keysas Loaded: loaded (/etc/systemd/system/keysas.service; enabled; preset: enabled) **### _Active: active (exited)_** since Fri 2024-04-26 15:08:52 EEST; 57min ago Process: 724 ExecStart=/bin/true (code=exited, status=0/SUCCESS) Main PID: 724 (code=exited, status=0/SUCCESS) CPU: 12ms any guidelines ??