<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://wiki.zionetrix.net/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://wiki.zionetrix.net/feed.php">
        <title>Zionetrix - informatique:securite</title>
        <description></description>
        <link>https://wiki.zionetrix.net/</link>
        <image rdf:resource="https://wiki.zionetrix.net/_media/wiki:dokuwiki.svg" />
       <dc:date>2026-04-21T13:56:34+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:authentic?rev=1645038414&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:cacert.org?rev=1426602034&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:cas?rev=1518016012&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:clamav?rev=1423132642&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:cracklib?rev=1498469546&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:easyrsa?rev=1773160738&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:fail2ban?rev=1555512996&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:idp_shibboleth?rev=1480618761&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:index?rev=1701197105&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:installer_ca_custom?rev=1589274751&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:kerberos?rev=1478192953&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:letsencrypt?rev=1549305449&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:luksfs?rev=1464798944&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:manip_certificat_ssl?rev=1736499227&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:manip_keystore?rev=1711530389&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:paiement_atos_-_x64?rev=1328281299&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.zionetrix.net/informatique:securite:ssh_over_tor?rev=1380824817&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://wiki.zionetrix.net/_media/wiki:dokuwiki.svg">
        <title>Zionetrix</title>
        <link>https://wiki.zionetrix.net/</link>
        <url>https://wiki.zionetrix.net/_media/wiki:dokuwiki.svg</url>
    </image>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:authentic?rev=1645038414&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-02-16T19:06:54+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>authentic</title>
        <link>https://wiki.zionetrix.net/informatique:securite:authentic?rev=1645038414&amp;do=diff</link>
        <description>Authentic

Doc officielle (en partie obsolète) : &lt;https://authentic2.readthedocs.io/en/latest/&gt;

Configuration d&#039;une application cliente CAS

Pour cela, il faut accéder à l&#039;interface d&#039;admin d&#039;Authentic : &lt;https://connexion.exenple.fr/admin/&gt; (par exemple)

Puis, aller dans : Authentic2_Idp_Cas / Applications / Ajouter et renseigner le formulaire comme suit :</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:cacert.org?rev=1426602034&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-03-17T14:20:34+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>cacert.org</title>
        <link>https://wiki.zionetrix.net/informatique:securite:cacert.org?rev=1426602034&amp;do=diff</link>
        <description>CAcert.org

Installation manuelle du certificat sur Debian/Ubuntu

sudo mkdir /usr/local/share/ca-certificates/cacert.org
sudo wget -P /usr/local/share/ca-certificates/cacert.org http://www.cacert.org/certs/root.crt http://www.cacert.org/certs/class3.crt
sudo update-ca-certificates</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:cas?rev=1518016012&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2018-02-07T15:06:52+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>cas</title>
        <link>https://wiki.zionetrix.net/informatique:securite:cas?rev=1518016012&amp;do=diff</link>
        <description>SSO CAS

Installation

L&#039;installation est facilement réalisable à l&#039;aide du packet cas-toolbox téléchargeable ici et documenté ici. L&#039;installation sera réalisé dans entièrement à l&#039;aide d&#039;un utilisateur POSIX cas dédié.

La configuration de cas-toolbox</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:clamav?rev=1423132642&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-02-05T10:37:22+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>clamav</title>
        <link>https://wiki.zionetrix.net/informatique:securite:clamav?rev=1423132642&amp;do=diff</link>
        <description>Clamav

Déclarer/vérifer un virus nom reconnu

URL : &lt;http://cgi.clamav.net/sendvirus.cgi&gt;</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:cracklib?rev=1498469546&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-06-26T09:32:26+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>cracklib</title>
        <link>https://wiki.zionetrix.net/informatique:securite:cracklib?rev=1498469546&amp;do=diff</link>
        <description>Cracklib

Installation

	*  Installer le paquet cracklib-runtime : 
apt-get install cracklib-runtime

	*  Initialiser le dictionnaire :
		*  Récupérer le lien de la dernière version du dictionnaire sur la page du projet : &lt;https://github.com/cracklib/cracklib/releases&gt;
		*  Télécharger le dictionnaire dans un dossier temporaire :</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:easyrsa?rev=1773160738&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-03-10T16:38:58+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>easyrsa</title>
        <link>https://wiki.zionetrix.net/informatique:securite:easyrsa?rev=1773160738&amp;do=diff</link>
        <description>EasyRSA

Installation

Via le paquet Debian


apt install easy-rsa
make-cadir /etc/easyrsa
mkdir /var/lib/easyrsa
cat &lt;&lt; EOF &gt; /usr/local/sbin/easyrsa
#!/bin/bash
export EASYRSA=/etc/easyrsa
export EASYRSA_PKI=/var/lib/easyrsa

cd &quot;\$EASYRSA&quot;
./easyrsa &quot;\$@&quot;
exit \$?
EOF
chmod 755 /usr/local/sbin/easyrsa</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:fail2ban?rev=1555512996&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2019-04-17T14:56:36+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>fail2ban</title>
        <link>https://wiki.zionetrix.net/informatique:securite:fail2ban?rev=1555512996&amp;do=diff</link>
        <description>Fail2ban

Installation

apt-get install fail2ban
initiptables
Utilisation

Apache
apache-authfiltermyapp
	*  Créer le fichier /etc/fail2ban/filter.d/myapp.conf : 

[Definition]
failregex = \[client &lt;HOST&gt;\] user .* (authentication failure|not found|password mismatch).*$
ignoreregex =</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:idp_shibboleth?rev=1480618761&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2016-12-01T18:59:21+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>idp_shibboleth</title>
        <link>https://wiki.zionetrix.net/informatique:securite:idp_shibboleth?rev=1480618761&amp;do=diff</link>
        <description>Shibboleth

Cette doc explique la mise en place du service Shibboleth dans le cadre de la fédération d&#039;identité Renater. Ce service permet aux utilisateurs d&#039;un membre de la fédération de se connecter aux ressources (=applications, services, ...</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:index?rev=1701197105&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-28T18:45:05+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>index</title>
        <link>https://wiki.zionetrix.net/informatique:securite:index?rev=1701197105&amp;do=diff</link>
        <description>Informatique / Sécurité

	*  Fail2ban
	*  Manipulation certificat SSL
	*  Manipulation des fichiers keystores (Java)
	*  Paiement ATOS - x64
	*  SSH over Tor
	*  SSO CAS
	*  SSO Authentic
	*  Clamav
	*  CAcert.org
	*  LuksFS
	*  Kerberos
	*  IDP Shibboleth
	*  Cracklib
	*  Let&#039;s Encrypt
	*  EasyRSA</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:installer_ca_custom?rev=1589274751&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2020-05-12T09:12:31+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>installer_ca_custom</title>
        <link>https://wiki.zionetrix.net/informatique:securite:installer_ca_custom?rev=1589274751&amp;do=diff</link>
        <description>Installer le certificat d&#039;une autorité de certification personnelle

	*  Créer le dossier /usr/local/share/ca-certificates/maCA et placer le certificat de l&#039;autorisé dans le fichier /usr/local/share/ca-certificates/maCA/maCA.crt (extension de fichier</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:kerberos?rev=1478192953&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2016-11-03T17:09:13+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>kerberos</title>
        <link>https://wiki.zionetrix.net/informatique:securite:kerberos?rev=1478192953&amp;do=diff</link>
        <description>Kerberos

S&#039;authentifier

kinit -V user@REALM

Lister les authentification

klist

Dans une keytab : 

klist  -k -t /path/to/file.keytab</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:letsencrypt?rev=1549305449&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2019-02-04T18:37:29+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>letsencrypt</title>
        <link>https://wiki.zionetrix.net/informatique:securite:letsencrypt?rev=1549305449&amp;do=diff</link>
        <description>Let&#039;s Encrypt

Installation de l&#039;agent certbot

apt install certbot
certboticiauto
wget -O /usr/local/sbin/certbot-auto https://dl.eff.org/certbot-auto
chmod 755 /usr/local/sbin/certbot-auto



acme.sh

Pré-configuration d&#039;Apache

	*  Créer le dossier qui servira aux</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:luksfs?rev=1464798944&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2016-06-01T16:35:44+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>luksfs</title>
        <link>https://wiki.zionetrix.net/informatique:securite:luksfs?rev=1464798944&amp;do=diff</link>
        <description>Luks FS

Formater la partition

pwgen -1 &gt; /root/.luks.pwd
# Format partition
cryptsetup -q --use-urandom luksFormat /dev/vg/lv /root/.luks.pwd

# Creating random keyfile for crypted partition
dd if=/dev/urandom of=/root/.luks.key bs=1024 count=4

# Setting permission on key/pass files
chmod 0500 /root/.luks.pwd /root/.luks.key

#Add new key on crypted partition
cryptsetup luksAddKey /dev/vg/lv

# Active crypted partition
cryptsetup luksOpen /dev/vg/lv mylv --key-file /root/.luks.key

# Creating…</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:manip_certificat_ssl?rev=1736499227&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-01-10T08:53:47+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>manip_certificat_ssl</title>
        <link>https://wiki.zionetrix.net/informatique:securite:manip_certificat_ssl?rev=1736499227&amp;do=diff</link>
        <description>Manipulation de certificats SSL

Générer un CSR

Version simple

openssl req -newkey rsa:2048 -subj /CN=example.com -nodes -keyout example.com.key -out example.com.csr

ou

CN=&quot;domain.tld&quot;
FILE=cert-domain.tld
openssl req -newkey rsa:2048 -subj /CN=$CN -nodes -keyout $FILE.key -out $FILE.csr</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:manip_keystore?rev=1711530389&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-03-27T09:06:29+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>manip_keystore</title>
        <link>https://wiki.zionetrix.net/informatique:securite:manip_keystore?rev=1711530389&amp;do=diff</link>
        <description>Manipulation des fichiers keystores (Java)

Chemin par défaut du keystore utilisé par Java

$JAVA_HOME/lib/security/cacerts

Mot de passe par défaut du keystore : changeit

Ajouter une autorité de certification

keytool -import -trustcacerts -alias MyCA -file /path/to/ca.crt -keystore /path/to/keystore</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:paiement_atos_-_x64?rev=1328281299&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-02-03T15:01:39+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>paiement_atos_-_x64</title>
        <link>https://wiki.zionetrix.net/informatique:securite:paiement_atos_-_x64?rev=1328281299&amp;do=diff</link>
        <description>Paiement ATOS - x64

Si vous possèdez une distrib en x64 avec un site marchand (ie: Prestashop) vous pouvez rencontrer des problèmes avec les binaires fournis par Atos. En effet ceux ci cont compilé pour du 32 bits. 

Il faut dnc installer un librairie capable de lire le 32 bits :</description>
    </item>
    <item rdf:about="https://wiki.zionetrix.net/informatique:securite:ssh_over_tor?rev=1380824817&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2013-10-03T18:26:57+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>ssh_over_tor</title>
        <link>https://wiki.zionetrix.net/informatique:securite:ssh_over_tor?rev=1380824817&amp;do=diff</link>
        <description>Mais comment donc faire passer une connexion ssh via Tor ?

On ajoute le dépôt Tor à notre distrib 
#Tor
deb http://deb.torproject.org/torproject.org wheezy main

Puis on récupère le clef du dépôt
gpg --keyserver keys.gnupg.net --recv 886DDD89
gpg --export A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89 | sudo apt-key add -</description>
    </item>
</rdf:RDF>
