ach-master.git
8 years agoMerge branch 'master' of github.com:BetterCrypto/Applied-Crypto-Hardening
Aaron Kaplan [Sun, 29 Mar 2015 20:18:44 +0000 (22:18 +0200)]
Merge branch 'master' of github.com:BetterCrypto/Applied-Crypto-Hardening

8 years agoremove some slides at the end
Aaron Kaplan [Sun, 29 Mar 2015 20:18:22 +0000 (22:18 +0200)]
remove some slides at the end

8 years agoRecommend OCSP stapling
Pepi Zawodsky [Sun, 29 Mar 2015 20:17:00 +0000 (22:17 +0200)]
Recommend OCSP stapling

8 years agoMerge branch 'master' of github.com:BetterCrypto/Applied-Crypto-Hardening
Aaron Kaplan [Sun, 29 Mar 2015 20:14:00 +0000 (22:14 +0200)]
Merge branch 'master' of github.com:BetterCrypto/Applied-Crypto-Hardening

8 years agoadd sslyze & screenshots
Aaron Kaplan [Sun, 29 Mar 2015 20:13:48 +0000 (22:13 +0200)]
add sslyze & screenshots

8 years agoAdded VM recommendation for RNGs and caveat for cipher strings.
Pepi Zawodsky [Sun, 29 Mar 2015 20:11:46 +0000 (22:11 +0200)]
Added VM recommendation for RNGs and caveat for cipher strings.

8 years agoless defensive status statement.
Pepi Zawodsky [Sun, 29 Mar 2015 20:02:31 +0000 (22:02 +0200)]
less defensive status statement.

8 years agoChanged filename of SSLLas screenshot so LaTeX will not be confused by extension...
Pepi Zawodsky [Sun, 29 Mar 2015 19:57:00 +0000 (21:57 +0200)]
Changed filename of SSLLas screenshot so LaTeX will not be confused by extension parsing.

8 years agoMerge branch 'master' of github:BetterCrypto/Applied-Crypto-Hardening
Pepi Zawodsky [Sun, 29 Mar 2015 19:47:55 +0000 (21:47 +0200)]
Merge branch 'master' of github:BetterCrypto/Applied-Crypto-Hardening

8 years agoUpdated Screenshot for SSLLabs. Disable RC4.
Pepi Zawodsky [Sun, 29 Mar 2015 19:47:48 +0000 (21:47 +0200)]
Updated Screenshot for SSLLabs. Disable RC4.

8 years agoMerge branch 'master' of github.com:BetterCrypto/Applied-Crypto-Hardening
Aaron Kaplan [Sun, 29 Mar 2015 19:45:08 +0000 (21:45 +0200)]
Merge branch 'master' of github.com:BetterCrypto/Applied-Crypto-Hardening

8 years agoadd slides with questions for organisations how they can
Aaron Kaplan [Sun, 29 Mar 2015 19:44:11 +0000 (21:44 +0200)]
add slides with questions for organisations how they can
achieve crypto deployment agility

8 years agoAdded new screenshot for SSLLabs test for bettercrypto.org
Pepi Zawodsky [Sun, 29 Mar 2015 19:42:32 +0000 (21:42 +0200)]
Added new screenshot for SSLLabs test for bettercrypto.org

8 years agoChanged date format to ISO8601
Pepi Zawodsky [Sun, 29 Mar 2015 19:23:07 +0000 (21:23 +0200)]
Changed date format to ISO8601

8 years agoadd license
Aaron Kaplan [Sun, 29 Mar 2015 19:00:45 +0000 (21:00 +0200)]
add license

8 years agoinitial slide deck for trainings
Aaron Kaplan [Sun, 29 Mar 2015 18:58:38 +0000 (20:58 +0200)]
initial slide deck for trainings

8 years agoadd comment on openvpn duplexing
Aaron Zauner [Mon, 16 Mar 2015 16:08:46 +0000 (17:08 +0100)]
add comment on openvpn duplexing

8 years agoRevert "comment-out OpenVPN, see GitHub #91"
Aaron Zauner [Mon, 16 Mar 2015 15:54:20 +0000 (16:54 +0100)]
Revert "comment-out OpenVPN, see GitHub #91"

This reverts commit 7b6fd17814acdbb2304ca3e84e99b02fe919abe6.

8 years agoMerge pull request #99 from shotty1/master
Aaron Zauner [Sat, 7 Mar 2015 16:25:15 +0000 (17:25 +0100)]
Merge pull request #99 from shotty1/master

Added -sha256 for generating keys

8 years agoAdded -sha256 for generating keys
shotty1 [Sat, 7 Mar 2015 11:24:47 +0000 (12:24 +0100)]
Added -sha256 for generating keys

Please check if this is OK. It improved the ssllabs results for me, removing the warning about SHA1.

8 years agocomment-out OpenVPN, see GitHub #91
Aaron Zauner [Wed, 18 Feb 2015 18:45:16 +0000 (19:45 +0100)]
comment-out OpenVPN, see GitHub #91

8 years agoMerge pull request #95 from sebix/cherokee-webserver
Aaron Zauner [Wed, 18 Feb 2015 18:37:43 +0000 (19:37 +0100)]
Merge pull request #95 from sebix/cherokee-webserver

Adding section for cherokee webserver

8 years agoMerge pull request #94 from sebix/stunnel
Aaron Zauner [Wed, 18 Feb 2015 18:37:19 +0000 (19:37 +0100)]
Merge pull request #94 from sebix/stunnel

Adding stunnel section to proxies

8 years agoMerge pull request #96 from BetterCrypto/revert-80-master
Aaron Zauner [Wed, 18 Feb 2015 18:34:40 +0000 (19:34 +0100)]
Merge pull request #96 from BetterCrypto/revert-80-master

Revert "Adding prosody"

8 years agoRevert "Adding prosody"
Aaron Zauner [Wed, 18 Feb 2015 18:34:30 +0000 (19:34 +0100)]
Revert "Adding prosody"

8 years agoAdding section for cherokee webserver
Sebastian Wagner [Wed, 18 Feb 2015 11:12:42 +0000 (12:12 +0100)]
Adding section for cherokee webserver

8 years agoAdding stunnel section to proxies
Sebastian Wagner [Fri, 13 Feb 2015 09:42:23 +0000 (10:42 +0100)]
Adding stunnel section to proxies

8 years agoMerge pull request #92 from sebix/master
Aaron Zauner [Fri, 13 Feb 2015 06:49:29 +0000 (07:49 +0100)]
Merge pull request #92 from sebix/master

Add certificate chain files to configs of apache and lighttpd

8 years agoMerge pull request #93 from 2001db8/master
Aaron Zauner [Fri, 13 Feb 2015 06:49:10 +0000 (07:49 +0100)]
Merge pull request #93 from 2001db8/master

Corrected the link for the SSL Labs Best Practices Guide

8 years agoCorrected link for SSL Labs Best Practices Guide
Jens Roesen [Fri, 6 Feb 2015 14:32:25 +0000 (15:32 +0100)]
Corrected link for SSL Labs Best Practices Guide

Link was 404. Changed it for a working one pointing to version 1.3 of
the guide.

8 years agoMerge pull request #83 from DigNative/pdfmapfile
Aaron Zauner [Sat, 24 Jan 2015 23:06:57 +0000 (00:06 +0100)]
Merge pull request #83 from DigNative/pdfmapfile

Modifying `\pdfmapfile' modifiers to not issue warnings on duplicate font map entries anymore.

8 years agoMerge pull request #85 from DigNative/neboltai-jpg
Aaron Zauner [Sat, 24 Jan 2015 23:06:47 +0000 (00:06 +0100)]
Merge pull request #85 from DigNative/neboltai-jpg

File `neboltai.png` is actually a JPG file.

8 years agoMerge pull request #84 from DigNative/ignore-configfiles
Aaron Zauner [Sat, 24 Jan 2015 23:04:59 +0000 (00:04 +0100)]
Merge pull request #84 from DigNative/ignore-configfiles

Adding `/src/configfiles.txt` to ignore list.

8 years agoAdd cert chains for apache and lighttpd
Sebastian Wagner [Sat, 24 Jan 2015 13:00:08 +0000 (14:00 +0100)]
Add cert chains for apache and lighttpd

8 years agoMerge pull request #87 from julianladisch/Header-always-add
Aaron Zauner [Fri, 12 Dec 2014 20:25:54 +0000 (21:25 +0100)]
Merge pull request #87 from julianladisch/Header-always-add

HSTS Apache: Header always add/set

8 years agoHSTS Apache: Header always add/set
julianladisch [Fri, 12 Dec 2014 15:46:21 +0000 (16:46 +0100)]
HSTS Apache: Header always add/set

Add "always" as Redirections and "Forbidden" pages should also get HSTS:
https://httpd.apache.org/docs/2.4/mod/mod_headers.html

Replace "add" by "set" to prevent adding a second HSTS field: "If an STS
header field is included, the HSTS Host MUST include only one such
header field." https://tools.ietf.org/html/rfc6797#section-7.1

8 years agoMerge pull request #86 from julianladisch/Header-always-set
Aaron Zauner [Fri, 12 Dec 2014 15:02:31 +0000 (16:02 +0100)]
Merge pull request #86 from julianladisch/Header-always-set

HSTS Apache: Header always set

8 years agoHSTS Apache: Header always set
julianladisch [Fri, 12 Dec 2014 14:58:02 +0000 (15:58 +0100)]
HSTS Apache: Header always set

Redirections and "Forbidden" pages should also get HSTS.

8 years agofixed path for prosody (#81)
Aaron Zauner [Sun, 16 Nov 2014 15:34:57 +0000 (16:34 +0100)]
fixed path for prosody (#81)

8 years agopath was wrong
Aaron Kaplan [Mon, 10 Nov 2014 19:50:41 +0000 (20:50 +0100)]
path was wrong

8 years agoremoved the supporting older clients as requested by Adi .
Aaron Kaplan [Mon, 10 Nov 2014 19:44:18 +0000 (20:44 +0100)]
removed the supporting older clients as requested by Adi .
Why? Because the POODLE killed it ;-)
Older clients which do not support SNI can't speak TLSv1.0 and above.
We don't support SSLv3 anymore anyway.

8 years agoMerge github.com:BetterCrypto/Applied-Crypto-Hardening
Aaron Kaplan [Mon, 10 Nov 2014 19:11:16 +0000 (20:11 +0100)]
Merge github.com:BetterCrypto/Applied-Crypto-Hardening

8 years agominor
Aaron Kaplan [Mon, 10 Nov 2014 19:06:45 +0000 (20:06 +0100)]
minor

8 years agoFile `neboltai.png` is actually a JPG file.
René Schwarz [Sat, 8 Nov 2014 22:26:21 +0000 (23:26 +0100)]
File `neboltai.png` is actually a JPG file.

A `file src/neboltai.png` reveals that this file is actually a JPG file:

    $ file neboltai.png
    neboltai.png: JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1596x2225, frames 3

Changed extension accordingly.

8 years agoAdding `/src/configfiles.txt` to ignore list.
René Schwarz [Sat, 8 Nov 2014 17:58:46 +0000 (18:58 +0100)]
Adding `/src/configfiles.txt` to ignore list.

The `/src/common/configfiles.tex` file creates the file `/src/configfiles.txt` during compilation, which is an auxiliary file containing all config files used/existing (I am not sure). However, this file should not be committed to the repository, at it is an auxiliary file created during compilation.

8 years agoModifying `\pdfmapfile' modifiers to not issue warnings on duplicate font map entries...
René Schwarz [Sat, 8 Nov 2014 17:46:11 +0000 (18:46 +0100)]
Modifying `\pdfmapfile' modifiers to not issue warnings on duplicate font map entries anymore.

When tried to compile the document on a Windows machine using latest MiKTeX and recent versions of all LaTeX packages included in the full installation, one can notice around 150 warnings thrown because the `system.tex' file contains two lines to include the font map files of `SourceCodePro' and `opensans' using the `\pdfmapfile' command. Because the modifier `+' is used, warnings are thrown for each font map which is already included by default for the document.

IMHO it is better to use the `=' modifier, which changes the behavior a little bit: The `+' modifier reads the specified font map and ignores all duplicate font map entries (a warning is issued), while the `=' modifier reads the specified font map and replaces matching font map entries with the new entries (no warning issued). I think this is the desired behavior.

For additional information refer to the PDFTeX documentation (`pdftex-a.pdf', r655 as of November 23, 2010) on pages 24 et seq.

8 years agoremove tlsv1 exclusion
Aaron Zauner [Thu, 6 Nov 2014 19:09:23 +0000 (20:09 +0100)]
remove tlsv1 exclusion

8 years agoMerge pull request #82 from stasic/patch-3
AaronK [Thu, 6 Nov 2014 06:19:01 +0000 (07:19 +0100)]
Merge pull request #82 from stasic/patch-3

added ubuntu 14.10

8 years agoadded ubuntu 14.10
Arsen Stasic [Wed, 5 Nov 2014 19:49:25 +0000 (20:49 +0100)]
added ubuntu 14.10

8 years agoMerge pull request #80 from MeikoDis/master
Aaron Zauner [Wed, 5 Nov 2014 13:38:12 +0000 (14:38 +0100)]
Merge pull request #80 from MeikoDis/master

Adding prosody

8 years agoText adjusted.
MeikoDis [Wed, 5 Nov 2014 13:31:03 +0000 (13:31 +0000)]
Text adjusted.

8 years agoRecommended Cipherstring
MeikoDis [Wed, 5 Nov 2014 09:44:28 +0000 (09:44 +0000)]
Recommended Cipherstring

8 years agoRC4, SHA1 and MD5
MeikoDis [Wed, 5 Nov 2014 00:08:38 +0000 (00:08 +0000)]
RC4, SHA1 and MD5

8 years agoCorrection2
MeikoDis [Wed, 5 Nov 2014 00:03:42 +0000 (00:03 +0000)]
Correction2

8 years agoCorrection
MeikoDis [Tue, 4 Nov 2014 23:59:38 +0000 (23:59 +0000)]
Correction

8 years agoCiphers, curve and depth added
MeikoDis [Tue, 4 Nov 2014 23:54:14 +0000 (23:54 +0000)]
Ciphers, curve and depth added

8 years agoMerge branch 'master' of github.com:MeikoDis/Applied-Crypto-Hardening
MeikoDis [Tue, 4 Nov 2014 22:53:43 +0000 (22:53 +0000)]
Merge branch 'master' of github.com:MeikoDis/Applied-Crypto-Hardening

8 years agoMerge https://github.com/BetterCrypto/Applied-Crypto-Hardening
Aaron Zauner [Sun, 2 Nov 2014 00:00:35 +0000 (01:00 +0100)]
Merge https://github.com/BetterCrypto/Applied-Crypto-Hardening

8 years agoMerge pull request #77 from DigNative/master
Aaron Zauner [Sun, 2 Nov 2014 00:00:29 +0000 (01:00 +0100)]
Merge pull request #77 from DigNative/master

Document did not compile under Windows, typo fixes

8 years agoMerge https://github.com/DigNative/Applied-Crypto-Hardening
Aaron Zauner [Sat, 1 Nov 2014 23:59:51 +0000 (00:59 +0100)]
Merge https://github.com/DigNative/Applied-Crypto-Hardening

8 years agoMerge pull request #78 from chdorb/patch-1
Aaron Zauner [Sat, 1 Nov 2014 23:58:28 +0000 (00:58 +0100)]
Merge pull request #78 from chdorb/patch-1

Update webserver.tex

8 years agoMerge pull request #70 from blakefrantz/master
Aaron Zauner [Sat, 1 Nov 2014 23:57:51 +0000 (00:57 +0100)]
Merge pull request #70 from blakefrantz/master

fixed small typos in IIS section

8 years agoMerge pull request #71 from oparoz/patch-1
Aaron Zauner [Sat, 1 Nov 2014 23:56:23 +0000 (00:56 +0100)]
Merge pull request #71 from oparoz/patch-1

Wrong verb for HSTS header

8 years agoMerge pull request #79 from stasic/patch-2
AaronK [Tue, 28 Oct 2014 22:57:00 +0000 (23:57 +0100)]
Merge pull request #79 from stasic/patch-2

added freebsd 10
Thx Arsen!

8 years agoadded freebsd 10
Arsen Stasic [Tue, 28 Oct 2014 21:23:21 +0000 (22:23 +0100)]
added freebsd 10

added ssh signature for freebsd 10

8 years agoUpdate webserver.tex
chdorb [Thu, 23 Oct 2014 12:33:23 +0000 (14:33 +0200)]
Update webserver.tex

Just a little lack of conjugation.

8 years agoChange email address
David Durvaux [Wed, 22 Oct 2014 07:37:15 +0000 (09:37 +0200)]
Change email address

8 years agoadd all the things
Aaron Zauner [Tue, 21 Oct 2014 08:10:35 +0000 (10:10 +0200)]
add all the things

8 years agoadd summary paper on curves progress within CFRG
Aaron Zauner [Tue, 21 Oct 2014 07:57:01 +0000 (09:57 +0200)]
add summary paper on curves progress within CFRG

8 years agoadd slides on IETF
Aaron Zauner [Tue, 21 Oct 2014 07:55:01 +0000 (09:55 +0200)]
add slides on IETF

8 years agostill minor modifications
Aaron Kaplan [Mon, 20 Oct 2014 22:26:48 +0000 (00:26 +0200)]
still minor modifications

8 years agoreplace medical-test.jpg picture :)
Aaron Kaplan [Mon, 20 Oct 2014 22:12:36 +0000 (00:12 +0200)]
replace medical-test.jpg picture :)
minor changes to the text

8 years agookay, I think we are ready for the presentation tomorrow
Aaron Kaplan [Mon, 20 Oct 2014 21:59:56 +0000 (23:59 +0200)]
okay, I think we are ready for the presentation tomorrow

8 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Mon, 20 Oct 2014 21:52:30 +0000 (23:52 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

8 years agorestructure, last slides
Aaron Kaplan [Mon, 20 Oct 2014 21:52:15 +0000 (23:52 +0200)]
restructure, last slides

8 years agofinish attacks part
Aaron Zauner [Mon, 20 Oct 2014 21:48:26 +0000 (23:48 +0200)]
finish attacks part

8 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Mon, 20 Oct 2014 21:12:23 +0000 (23:12 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

8 years agomore images
Aaron Kaplan [Mon, 20 Oct 2014 21:12:06 +0000 (23:12 +0200)]
more images

8 years agomore slides
Aaron Kaplan [Mon, 20 Oct 2014 21:11:35 +0000 (23:11 +0200)]
more slides

8 years agoget rid of company logo
Aaron Zauner [Mon, 20 Oct 2014 21:02:50 +0000 (23:02 +0200)]
get rid of company logo

8 years agoadd slides for attacks (seperate)
Aaron Zauner [Mon, 20 Oct 2014 20:54:17 +0000 (22:54 +0200)]
add slides for attacks (seperate)

8 years agodoes not work... remove \input
Aaron Kaplan [Mon, 20 Oct 2014 20:39:50 +0000 (22:39 +0200)]
does not work... remove \input

8 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Mon, 20 Oct 2014 20:38:13 +0000 (22:38 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

8 years agoadd more slides
Aaron Kaplan [Mon, 20 Oct 2014 20:37:56 +0000 (22:37 +0200)]
add more slides

8 years agoinclude attack.tex in agenda.md
Aaron Zauner [Mon, 20 Oct 2014 20:33:32 +0000 (22:33 +0200)]
include attack.tex in agenda.md

8 years agoadd images
Aaron Kaplan [Mon, 20 Oct 2014 20:30:07 +0000 (22:30 +0200)]
add images

8 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Mon, 20 Oct 2014 20:29:36 +0000 (22:29 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

Conflicts:
presentations/HACK.LU-2014/presentation/agenda.md

8 years agomerge in David's changes and adapt
Aaron Kaplan [Mon, 20 Oct 2014 20:28:04 +0000 (22:28 +0200)]
merge in David's changes and adapt

8 years agoadd attacks.tex (still issues with compiling that though)
Aaron Zauner [Mon, 20 Oct 2014 20:27:11 +0000 (22:27 +0200)]
add attacks.tex (still issues with compiling that though)

8 years agoadd attacks.tex (still issues with compiling that though)
Aaron Zauner [Mon, 20 Oct 2014 20:26:53 +0000 (22:26 +0200)]
add attacks.tex (still issues with compiling that though)

8 years agoRemoving XXX
David Durvaux [Mon, 20 Oct 2014 20:25:07 +0000 (22:25 +0200)]
Removing XXX

8 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Mon, 20 Oct 2014 20:24:20 +0000 (22:24 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

8 years agomore slides
Aaron Kaplan [Mon, 20 Oct 2014 20:24:11 +0000 (22:24 +0200)]
more slides

8 years agoAdding history
David Durvaux [Mon, 20 Oct 2014 19:54:48 +0000 (21:54 +0200)]
Adding history

8 years agoadd comment in README: many small commits are better
Aaron Kaplan [Mon, 20 Oct 2014 16:07:58 +0000 (18:07 +0200)]
add comment in README: many small commits are better

8 years agoModifications after comment from @krono.
René Schwarz [Mon, 20 Oct 2014 06:11:59 +0000 (08:11 +0200)]
Modifications after comment from @krono.

8 years agointermediate version, add missing files
Aaron Kaplan [Sun, 19 Oct 2014 23:50:08 +0000 (01:50 +0200)]
intermediate version, add missing files

8 years agointermediate version for hack.lu
Aaron Kaplan [Sun, 19 Oct 2014 23:48:56 +0000 (01:48 +0200)]
intermediate version for hack.lu

8 years agoCorrecting typo in HACK.LU 2014 presentation: It's not `Diffie-Helleman`, it's `Diffi...
René Schwarz [Sun, 19 Oct 2014 21:12:40 +0000 (23:12 +0200)]
Correcting typo in HACK.LU 2014 presentation: It's not `Diffie-Helleman`, it's `Diffie-Hellman`.

8 years agoMerge remote-tracking branch 'remotes/upstream/master'
René Schwarz [Sun, 19 Oct 2014 21:06:55 +0000 (23:06 +0200)]
Merge remote-tracking branch 'remotes/upstream/master'