pfx export key and crt

Get the private .key from the .pfx certificate

openssl pkcs12 -in my_certificate.pfx -nocerts -out my_certificate-encrypted.key


Get the decrypted .key file from the encrypted private .key file

openssl rsa -in my_certificate-encrypted.key -out my_certificate.key



Get the .crt file from the .pfx file

openssl pkcs12 -in my_certificate.pfx -clcerts -nokeys -out my_certificate.crt 



REF:

https://blog.christian-schou.dk/convert-pfx-to-crt-and-key-file-with-openssl/

Host header attack - Nginx

設定

nginx 假如 host/ http_host 不是自家 domain 導出 444

nginx 444 表示中斷連線, 連 header 都不會發出來


    if ( $host !~* ^(mydomain.com)$ ) {

        return 444;

    }

    if ( $http_host !~* ^(mydomain.com)$ ) {

        return 444;

    }


假如 nginx 有多個 vhost 也要一起設定, 否則運作不會成功. 

curl (60) peer’s certificate issuer is not recognized.

更新 SSL 後 CURL 失效

1. 將新的 .crt 拷貝至 /etc/pki/ca-trust/source/anchors

2. 執行 update-ca-trust extract

3. 測試 curl 是否可以重新讀取


ref: 

https://ep.gnt.md/index.php/curl-60-peers-certificate-issuer-is-not-recognized/

Install VirtualBox Guest Additions in CentOS

Step 1. update to last repo

# yum -y install epel-release
# yum -y update
# yum install make gcc kernel-headers kernel-devel perl dkms bzip2
# reboot


Step 2. mount CDROM and install 

# mkdir /mnt/cdrom
# mount /dev/cdrom /mnt/cdrom
# cd /mnt/cdrom
# ./VBoxLinuxAdditions.run
# reboot


CentOS 7 Install NFS Server / Client and Setting

NFS allows a linux server to share directories with other UNIX clients over network. NFS server exports a directory and NFS client mounts this directory. RHEL 7 supports two version of NFS – NFSv3 and NFSv4.

NFS server and RPC processes
starting the nfs-server process starts the NFS server and other RPC processes. RPC processes includes:
– rpc.statd : implements monitoring protocol (NSM) between NFS client and NFS server
– rpc.mountd : NFS mount daemon that implements the server side of the mount requests from NFSv3 clients.
– rpc.idmapd : Maps NFSv4 names and local UIDs and GIDs
– rpc.rquotad : provides user quota information for remote users.

Configuring NFS server
1. Install the required nfs packages if not already installed on the server :
# yum install nfs-utils rpcbind

2. Enable the services at boot time:
#  systemctl enable nfs-server
#  systemctl enable rpcbind
#  systemctl enable nfs-lock
In RHEL7.1 (nfs-utils-1.3.0-8.el7) enabling nfs-lock does not work (No such file or directory). it does not need to be enabled since rpc-statd.service is static.
#  systemctl enable nfs-idmap
In RHEL7.1 (nfs-utils-1.3.0-8.el7) this does not work (No such file or directory). it does not need to be enabled since nfs-idmapd.service is static.

3. Start the NFS services:
#  systemctl start rpcbind
#  systemctl start nfs-server
#  systemctl start nfs-lock
#  systemctl start nfs-idmap
4. Check the status of NFS service:
# systemctl status nfs

5. Create a shared directory:
# mkdir /test

6. Export the directory. The format of the /etc/exports file is :
dir client1 (options) [client2(options)...]
Client options include (defaults are listed first) :
ro / rw :
a) ro : allow clients read only access to the share.
b) rw : allow clients read write access to the share.
sync / async :
a) sync : NFS server replies to request only after changes made by previous request are written to disk.
b) async : specifies that the server does not have to wait.
wdelay / no_wdelay
a) wdelay : NFS server delays committing write requests when it suspects another write request is imminent.
b) no_wdelay : use this option to disable to the delay. no_wdelay option can only be enabled if default sync option is enabled.
no_all_squash / all_squash :
a) no_all_squash : does not change the mapping of remote users.
b) all_squash : to squash all remote users including root.
root_squash / no_root_squash :
a) root_squash : prevent root users connected remotely from having root access. Effectively squashing remote root privileges.
b) no_root_squash : disable root squashing.

Example :
# vi /etc/exports/test *(rw)


7. Exporting the share :
# exportfs -r

-r re-exports entries in /etc/exports and sync /var/lib/nfs/etab with /etc/exports. The /var/lib/nfs/etab is the master export table. Other options that can be used with exportfs command are :
-a : exports entries in /etc/exports but do not synchronize with /var/lib/nfs/etab
-i : ignore entries in /etc/exports and uses command line arguments.
-u : un-export one or more directories
-o : specify client options on command line

8. Restart the NFS service:
# systemctl restart nfs-server

Configuring NFS client
1. Install the required nfs packages if not already installed on the server :
# yum install nfs-utils

2. Use the mount command to mount exported file systems. Syntax for the command:
mount -t nfs -o options host:/remote/export /local/directory

Eample :
# mount -t nfs -o ro,nosuid remote_host:/home /remote_home
This example does the following:
– It mounts /home from remote host (remote_host) on local mount point /remote_home.
– File system is mounted read-only and users are prevented from running a setuid program (-o ro,nosuid options).

3. Update /etc/fstab to mount NFS shares at boot time.
# vi /etc/fstab
remote_host:/home /remote_home nfs ro,nosuid 0 0

Firewalld services to be active on NFS server
For the NFS server to work, enable the nfs, mountd, and rpc-bind services in the relevant zone in the firewall-config application or using firewall-cmd :
# firewall-cmd --add-service=nfs --zone=internal --permanent
# firewall-cmd --add-service=mountd --zone=internal --permanent
# firewall-cmd --add-service=rpc-bind --zone=internal --permanent

Ref: 
https://www.thegeekdiary.com/centos-rhel-7-configuring-an-nfs-server-and-nfs-client/
























如何使用 OpenSSL 建立開發測試用途的自簽憑證 (Self-Signed Certificate)

1. 建立 ssl.conf 設定檔

[req]
prompt = no
default_md = sha256
default_bits = 2048
distinguished_name = dn
x509_extensions = v3_req

[dn]
C = TW
ST = Taiwan
L = Taipei
O = My Inc.
OU = IT Department
emailAddress = admin@example.com
CN = CA Disaplay Name

[v3_req]
subjectAltName = @alt_names

[alt_names]
DNS.1 = *.localhost
DNS.2 = localhost
DNS.3 = *.your.domain.name
DNS.4 = 192.168.1.100

2. 透過 OpenSSL 命令產生出自簽憑證與相對應的私密金鑰


openssl req -x509 -new -nodes -sha256 -utf8 -days 3650 -newkey rsa:2048 -keyout server.key -out server.crt -config ssl.conf


3. 透過 OpenSSL 命令產生 PKCS#12 憑證檔案 (*.pfx 或 *.p12), IIS才需要


openssl pkcs12 -export -in server.crt -inkey server.key -out server.pfx


4. 匯入自簽憑證到 WINDOWS 憑證 「受信任的根憑證授權單位」

Windows 請以「系統管理員身分」執行以下命令,即可將憑證匯入到 Windows 的憑證儲存區之中:


certutil -addstore -f "ROOT" server.crt

若要以手動方式匯入,可以參考以下步驟:


  • 開啟檔案總管,並滑鼠雙擊 server.crt 檔案
  • 點擊「安裝憑證」按鈕
  • 選取「目前使用者」並按「下一步」繼續
  • 選取「將所有憑證放入以下的存放區」並按下「瀏覽」按鈕
  • 選取「受信任的根憑證授權單位」並按下「確定」
  • 按「下一步」繼續
  • 按「完成」繼續
  • 在 安全性警告 視窗按下「是(Y)」即可完成設定

請注意:在匯入完成後 Google Chrome 瀏覽器可能不會立刻顯示這是個有效憑證 (因為快取的關係),但你只要過一段時間重開 Chrome 瀏覽器,即可看見網址列的變化,不會再出現紅色不安全的提示。



參考文章:

The Will Will Web ( 感謝保哥分享 )

https://blog.miniasp.com/post/2019/02/25/Creating-Self-signed-Certificate-using-OpenSSL