06 - Transport Layer Securit

Class: CSCE-465-63860


Theory: Network Access Control & Cloud Computing

Labs:


Examining the TLS Protocol

For these exercises you need to install Wireshark network sniffer from https://www.wireshark.org. It works for Windows and should also work for Mac. However, you might instead study the contents of Wireshark_SSL_SOLUTION_v7.0.pdf.

6.1

6.1) Catch TLS communication (for example from https://inside.dtu.dk/) with Wireshark sniffer and identify and show the messages. (Make sure you are not just re-activating an existing session – close/open browser or use another browser or go to some other site with https enabled).

6.2

6.2) Have a close look at the cipher suite negotiation. Which cipher suites are proposed by client and which one is chosen by server?

6.3

6.3) Read about Heartbleed attack (http://en.wikipedia.org/wiki/Heartbleed) and describe in short what the problem was?

6.4 (optional)

OpenSSH for Linux

6.5

6.5) Linux users can set up servers. Set up sshd to support key-based authentication. Several slightly different tutorials exist – Here is one: https://linuxhint.com/how-to-install-and-enable-openssh-on-ubuntu/ The sshd config file might already have been set up to allow key-based authentication

You can generate the key pair on the Linux system. If you want to generate RSA key pair simply omit the option to ssh-keygen

SSH client

6.6

6.6) Install and setup the popular PuTTY SSH client (https://www.puttygen.com/download-putty). Thereafter go to https://www.xshellz.com/ and create free shell account. Define a password for SSH. Finally use PuTTY as SSH client to access your new shell account at XSHELLZ.

6.7

6.7) With PuTTY was also installed the tool PuTTYgen which can generate key pairs for SSH. Generate RSA key pair with it and copy the public key (including ssh-rsa in the beginning) to your account at XSHELLZ. Attach it to the shell. In PuTTYgen remember to save the private key to a file on your laptop (protected by passphrase).

With PuTTY SSH client, access your shell with key-based authentication. For doing this, you need to install your private key file in PuTTY (at Connection->SSH->Auth->Credentials)

TLS version 1.3

6.8

6.8) Read about TLS version 1.3 (RFC 8446 released in 2020): https://www.a10networks.com/glossary/key-differences-between-tls-1-2-and-tls-1-3/ Make a short description of the improvements

SSH & port forwarding

6.9

6.9) Read about the possibilities, for instance here: https://www.ssh.com/academy/ssh/tunneling-example. Note down a few examples.