LITTLEBLACKDOG.COM Forum Index LITTLEBLACKDOG.COM

 
LWD LWD   FAQ FAQ   Memberlist Memberlist   Usergroups Usergroups   Active Topics Active Topics   Register Register  
  Profile Profile   Log in to check your private messages Log in to check your private messages   Log in Log in  
  Who is Online Who is Online   Image Gallery Image Gallery   Chat Chat   Search Search  
  LWDGear       LBDGear  

View next topic
View previous topic
Post new topic     Reply to topic   LITTLEBLACKDOG.COM Forum Index -> Operating Systems » OS - Linux
Author Message
ChrisDrass
Cat Chaser
Cat Chaser


Joined: 11 May 2004
Posts: 481

Post Posted: Fri Jan 14, 2005 6:59 pm   Post subject: SSL VPN Reply with quote Back to top  

I am trying to build an SSL VPN.

I want to have users go to an HTTPS page and enter their credentials. Once authenticated, the user would have a new browser window opened (a window in a window) where they would be local to the SSL server and could gain access to Intranet web sites.

I am not locked to a specific Distro or Browser.

Any ideas?
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
soup4you2
Tail-Wagger
Tail-Wagger


Joined: 15 Mar 2002
Posts: 2453
Location: Desolate wastelands of Virginia

Post Posted: Mon Jan 17, 2005 7:24 pm   Post subject: Reply with quote Back to top  

1 way would to use the pf firewall, then assign a account to the authpf shell and have some webpage use a ssh p1 connection to authenticate through the firewall and load a dynamic ruleset.

_________________
tomorrow will be canceled due to lack of interest
View user's profile Send private message Send e-mail
ChrisDrass
Cat Chaser
Cat Chaser


Joined: 11 May 2004
Posts: 481

Post Posted: Tue Jan 18, 2005 5:33 pm   Post subject: Reply with quote Back to top  

I found an opensource project that is working on this. It is called ssl-explorer.

They have the source code available so you can port it to whatever system you want. (you have to have J2RE 1.5 also)

They have packaged a windows version and a redhat version. I tried them both and the Windows version seems to be faster. They are functionally identical though.

It is really cool. If you are into this sort of thing, I recommend that you try it out.

It is at www.3sp.com
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
squashman
Big Dog
Big Dog


Joined: 08 Oct 2001
Posts: 3486
Location: 1265 Lombardi Ave.

Post Posted: Fri Mar 04, 2005 11:24 am   Post subject: Reply with quote Back to top  

ChrisDrass wrote:
It is really cool. If you are into this sort of thing, I recommend that you try it out.

It is at www.3sp.com


Started playing with it today. This is pretty fricken cool. I see alot of potential for this project.
View user's profile Send private message Send e-mail
squashman
Big Dog
Big Dog


Joined: 08 Oct 2001
Posts: 3486
Location: 1265 Lombardi Ave.

Post Posted: Sun Mar 06, 2005 7:50 pm   Post subject: Reply with quote Back to top  

Now I started using their SSH client as well. I love it.
http://www.sshtools.com/products/applications/sshterm-pro/sshterm-pro.jsp
View user's profile Send private message Send e-mail
squashman
Big Dog
Big Dog


Joined: 08 Oct 2001
Posts: 3486
Location: 1265 Lombardi Ave.

Post Posted: Sun Mar 06, 2005 9:51 pm   Post subject: Reply with quote Back to top  

Chris are you running this on Windows or LInux?
View user's profile Send private message Send e-mail
squashman
Big Dog
Big Dog


Joined: 08 Oct 2001
Posts: 3486
Location: 1265 Lombardi Ave.

Post Posted: Fri Jul 15, 2005 11:53 am   Post subject: Reply with quote Back to top  

Just read that SSL-Explorer now has a plugin to allow it to authenticate against the local password file on Unix and Linux systems.
View user's profile Send private message Send e-mail
squashman
Big Dog
Big Dog


Joined: 08 Oct 2001
Posts: 3486
Location: 1265 Lombardi Ave.

Post Posted: Wed Aug 23, 2006 9:50 pm   Post subject: Reply with quote Back to top  

There is now a VMWARE Applicance for SSL-Explorer.
http://h0bbel.p0ggel.org/2006/06/28/ssl-explorer-clientless-vpn-via-ssl/
View user's profile Send private message Send e-mail
Mahmoud
Cat Chaser
Cat Chaser


Joined: 24 Nov 2003
Posts: 896
Location: AE, Shj

Post Posted: Tue Oct 10, 2006 8:37 am   Post subject: Reply with quote Back to top  

what about OpenVPN? it uses SSL too
http://openvpn.net/
you can use it in many environments, even via web proxies where you specify web proxy information in your OpenVPN client

Quote:
1 way would to use the pf firewall, then assign a account to the authpf shell and have some webpage use a ssh p1 connection to authenticate through the firewall and load a dynamic ruleset.

I don't think this method encrypts sent data at all, it just uses SSH session for authenticating users and loading per-user firewall rules. so I think it still allows for ip spoofing attacks

_________________
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
dugg
Cat Chaser
Cat Chaser


Joined: 18 Jan 2001
Posts: 736
Location: 15 miles from Hell

Post Posted: Wed Oct 11, 2006 8:45 am   Post subject: Reply with quote Back to top  

Thanks for bumping the thread. Never heard of SSL-Explorer. Cool stuff.
View user's profile Send private message
squashman
Big Dog
Big Dog


Joined: 08 Oct 2001
Posts: 3486
Location: 1265 Lombardi Ave.

Post Posted: Thu Oct 12, 2006 9:14 pm   Post subject: Reply with quote Back to top  

Mahmoud wrote:
what about OpenVPN? it uses SSL too
http://openvpn.net/
you can use it in many environments, even via web proxies where you specify web proxy information in your OpenVPN client

Quote:
1 way would to use the pf firewall, then assign a account to the authpf shell and have some webpage use a ssh p1 connection to authenticate through the firewall and load a dynamic ruleset.

I don't think this method encrypts sent data at all, it just uses SSH session for authenticating users and loading per-user firewall rules. so I think it still allows for ip spoofing attacks


But then you need a client. SSL Explorer doesn't require you to install a client on your computer.
View user's profile Send private message Send e-mail
Display posts from previous:   
Post new topic     Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2002 phpBB Group
phpBB SEO
All times are GMT - 8 Hours

Help us keep advertisements off this site. Donate today!