WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ืขื˜ืœืขื›ืข ื‘ื™ื™ืฉืคื™ืœืŸ ืคื•ืŸ ืึธืจื’ืึทื ื™ื™ื–ื™ื ื’ ืคึฟื™ืจืžืข WiFi ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ื“ื™ืกืงืจื™ื™ื‘ื“. ื“ืึธ ืื™ืš ื•ื•ืขื˜ ื‘ืึทืฉืจื™ื™ึทื‘ืŸ ื•ื•ื™ ืื™ืš ื™ืžืคึผืœืึทืžืขื ืึทื“ ืึท ืขื ืœืขืš ืœื™ื™ื–ื•ื ื’ ืื•ืŸ ื“ื™ ืคึผืจืึธื‘ืœืขืžืก ืื™ืš ื’ืขืคึผืœืึธื ื˜ืขืจื˜ ื•ื•ืขืŸ ืงืึทื ืขืงื˜ื™ื ื’ ืื•ื™ืฃ ืคืึทืจืฉื™ื“ืขื ืข ื“ืขื•ื•ื™ืกืขืก. ืžื™ืจ ื•ื•ืขืœืŸ ื ื•ืฆืŸ ื“ื™ ื™ื’ื–ื™ืกื˜ื™ื ื’ LDAP ืžื™ื˜ ื’ืขื’ืจื™ื ื“ืขื˜ ื™ื•ื–ืขืจื–, ื™ื ืกื˜ืึทืœื™ืจืŸ FreeRadius ืื•ืŸ ืงืึทื ืคื™ื’ื™ืขืจ WPA2-Enterprise ืื•ื™ืฃ ื“ื™ Ubnt ืงืึธื ื˜ืจืึธืœืœืขืจ. ืึทืœืฅ ืžื™ื™ื ื˜ ืคึผืฉื•ื˜. ืœืืžื™ืจ ื–ืขื”ืŸโ€ฆ

ื ื‘ื™ืกืœ ื•ื•ืขื’ืŸ EAP ืžืขื˜ื”ืึธื“ืก

ืื™ื™ื“ืขืจ ืžื™ืจ ืึธื ื”ื™ื™ื‘ืŸ ื“ื™ ืึทืจื‘ืขื˜, ืžื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื‘ืึทืฉืœื™ืกืŸ ื•ื•ืึธืก ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ืคึฟืŸ ืžื™ืจ ื•ื•ืขืœืŸ ื ื•ืฆืŸ ืื™ืŸ ืื•ื ื“ื–ืขืจ ืœื™ื™ื–ื•ื ื’.

ืคึฟื•ืŸ ื•ื•ื™ืงื™ืคึผืขื“ื™ืข:

EAP ืื™ื– ืึท ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคืจื™ื™ืžื•ื•ืขืจืง ื•ื•ืึธืก ืื™ื– ืึธืคื˜ ื’ืขื ื™ืฆื˜ ืื™ืŸ ื•ื•ื™ื™ืจืœื™ืก ื ืขื˜ื•ื•ืึธืจืงืก ืื•ืŸ ืคื•ื ื˜-ืฆื•-ืคื•ื ื˜ ืงืึทื ืขืงืฉืึทื ื–. ื“ืขืจ ืคึฟืึธืจืžืึทื˜ ืื™ื– ื’ืขื•ื•ืขืŸ ืขืจืฉื˜ืขืจ ื“ื™ืกืงืจื™ื™ื‘ื“ ืื™ืŸ RFC 3748 ืื•ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ืื™ืŸ RFC 5247.
EAP ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ืึทืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ืคึฟืŸ, ืึทืจื™ื‘ืขืจืคื™ืจืŸ ืฉืœื™ืกืœืขืŸ ืื•ืŸ ืคึผืจืึธืฆืขืก ื“ื™ ืฉืœื™ืกืœืขืŸ ื“ื•ืจืš ืคึผืœื•ื’ื™ื ืก ื’ืขืจื•ืคืŸ EAP ืžืขื˜ื”ืึธื“ืก. ืขืก ื–ืขื ืขืŸ ืคื™ืœืข EAP ืžืขื˜ื”ืึธื“ืก, ื‘ื™ื™ื“ืข ื“ื™ืคื™ื™ื ื“ ืžื™ื˜ EAP ื–ื™ืš ืื•ืŸ ื“ื™ ืจืขืœืขืึทืกืขื“ ื“ื•ืจืš ื™ื—ื™ื“ ื•ื•ืขื ื“ืึธืจืก. EAP ื“ืขืคื™ื ื™ืจืŸ ื ื™ืฉื˜ ื“ื™ ืœื™ื ืง ืฉื™ื›ื˜ืข, ืขืก ื“ื™ืคื™ื™ื ื– ื‘ืœื•ื™ื– ื“ื™ ืึธื ื–ืึธื’ ืคึฟืึธืจืžืึทื˜. ื™ืขื“ืขืจ ืคึผืจืึธื˜ืึธืงืึธืœ ื•ื•ืึธืก ื ื™ืฆื˜ EAP ื”ืื˜ ื–ื™ื™ืŸ ืื™ื™ื’ืขื ืข EAP ืึธื ื–ืึธื’ ืขื ืงืึทืคึผืกื•ืœืึทื˜ื™ืึธืŸ ืคึผืจืึธื˜ืึธืงืึธืœ.

ื“ื™ ืžืขื˜ื”ืึธื“ืก ื–ื™ืš:

  • LEAP ืื™ื– ืึท ืคึผืจืึทืคึผืจื™ื™ืึทื˜ืขืจื™ ืคึผืจืึธื˜ืึธืงืึธืœ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื•ืจืš CISCO. ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื’ืขืคื•ื ืขืŸ. ื“ืขืจื•ื•ื™ื™ึทืœ ื ื™ื˜ ืจืขืงืึทืžืขื ื“ื™ื“ ืคึฟืึทืจ ื ื•ืฆืŸ
  • EAP-TLS ืื™ื– ื’ืขื–ื•ื ื˜ ื’ืขืฉื˜ื™ืฆื˜ ืฆื•ื•ื™ืฉืŸ ื•ื•ื™ื™ืจืœื™ืก ื•ื•ืขื ื“ืึธืจืก. ืขืก ืื™ื– ืึท ื–ื™ื›ืขืจ ืคึผืจืึธื˜ืึธืงืึธืœ ื•ื•ื™ื™ึทืœ ืขืก ืื™ื– ื“ืขืจ ืกืึทืงืกืขืกืขืจ ืฆื• ื“ื™ SSL ืกื˜ืึทื ื“ืึทืจื“ืก. ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ืขื ืงืœื™ืขื ื˜ ืื™ื– ื’ืึทื ืฅ ืงืึธืžืคึผืœื™ืฆื™ืจื˜. ืื™ืจ ื“ืึทืจืคึฟืŸ ืึท ืงืœื™ืขื ื˜ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ื“ื™ ืคึผืึทืจืึธืœ. ื’ืขืฉื˜ื™ืฆื˜ ืื•ื™ืฃ ืคื™ืœืข ืกื™ืกื˜ืขืžืขืŸ
  • EAP-TTLS - ื•ื•ื™ื™ื“ืœื™ ื’ืขืฉื˜ื™ืฆื˜ ืื•ื™ืฃ ืคื™ืœืข ืกื™ืกื˜ืขืžืขืŸ, ืึธืคืคืขืจืก ื’ื•ื˜ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื ื™ืฆืŸ PKI ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื‘ืœื•ื™ื– ืื•ื™ืฃ ื“ื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืกืขืจื•ื•ืขืจ
  • EAP-MD5 ืื™ื– ืืŸ ืื ื“ืขืจ ืึธืคึฟืŸ ื ืึธืจืžืึทืœ. ืึธืคืคืขืจืก ืžื™ื ื™ืžืึทืœ ื–ื™ื›ืขืจื”ื™ื™ึทื˜. ืฉืคึผื™ืจืขื•ื•ื“ื™ืง, ื˜ื•ื˜ ื ื™ืฉื˜ ืฉื˜ื™ืฆืŸ ืงืขื’ื ืฆื™ื™ึทื˜ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ืŸ ืฉืœื™ืกืœ ื“ื•ืจ
  • EAP-IKEv2 - ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ืื™ื ื˜ืขืจื ืขื˜ ื“ื•ืจื›ืคึฟืึทืœ ืขืงืกื˜ืฉืึทื ื’ืข ืคึผืจืึธื˜ืึธืงืึธืœ ื•ื•ืขืจืกื™ืข 2. ืคึผืจืึธื•ื•ื™ื“ืขืก ืงืขื’ื ืฆื™ื™ึทื˜ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ืŸ ืกืขืกื™ืข ืฉืœื™ืกืœ ืคืึทืจืœื™ื™ื’ืŸ ืฆื•ื•ื™ืฉืŸ ืงืœื™ืขื ื˜ ืื•ืŸ ืกืขืจื•ื•ืขืจ
  • PEAP ืื™ื– ืึท ืฉืœืึธืก ืœื™ื™ื–ื•ื ื’ ืฆื•ื•ื™ืฉืŸ CISCO, Microsoft ืื•ืŸ RSA Security ื•ื•ื™ ืึทืŸ ืึธืคึฟืŸ ื ืึธืจืžืึทืœ. ื•ื•ื™ื™ื“ืœื™ ื‘ื ื™ืžืฆื ืื™ืŸ ืคึผืจืึธื“ื•ืงื˜ืŸ, ื’ื™ื˜ ื–ื™ื™ืขืจ ื’ื•ื˜ ื–ื™ื›ืขืจืงื™ื™ึทื˜. ืขื ืœืขืš ืฆื• EAP-TTLS, ืจื™ืงื•ื•ื™ื™ืจื™ื ื’ ื‘ืœื•ื™ื– ืึท ืกืขืจื•ื•ืขืจ ื–ื™ื™ึทื˜ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ
  • PEAPv0/EAP-MSCHAPv2 - ื ืึธืš EAP-TLS, ื“ืึธืก ืื™ื– ื“ืขืจ ืฆื•ื•ื™ื™ื˜ ื•ื•ื™ื™ื“ืœื™ ื’ืขื•ื•ื™ื™ื ื˜ ื ืึธืจืžืึทืœ ืื™ืŸ ื“ืขืจ ื•ื•ืขืœื˜. ื’ืขื•ื•ื™ื™ื ื˜ ืงืœื™ืขื ื˜-ืกืขืจื•ื•ืขืจ ืฉื™ื™ื›ื•ืช ืื™ืŸ ืžื™ื™ืงืจืึธืกืึธืคึฟื˜, ืกื™ืกืงืึธ, ืขืคึผืœ, ืœื™ื ื•ืงืก
  • PEAPv1/EAP-GTC - ื‘ืืฉืืคืŸ ื“ื•ืจืš Cisco ื•ื•ื™ ืึทืŸ ืึธืœื˜ืขืจื ืึทื˜ื™ื•ื• ืฆื• PEAPv0/EAP-MSCHAPv2. ื˜ื•ื˜ ื ื™ืฉื˜ ื‘ืึทืฉื™ืฆืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื“ืึทื˜ืŸ ืื™ืŸ ืงื™ื™ืŸ ื•ื•ืขื’. ื ื™ื˜ ื’ืขืฉื˜ื™ืฆื˜ ืื•ื™ืฃ Windows OS
  • EAP-FAST ืื™ื– ืึท ืžืขื˜ืึธื“ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื•ืจืš Cisco ืฆื• ืคืึทืจืจื™ื›ื˜ืŸ ื“ื™ ืฉืึธืจื˜ืงืึธืžื™ื ื’ืก ืคื•ืŸ LEAP. ื ื™ืฆื˜ ืคึผืจืึธื˜ืขืงื˜ืขื“ ืึทืงืกืขืก ืงืจืขื“ืขื ื˜ื™ืึทืœ (PAC). ื’ืึธืจ ืึทื ืคื™ื ื™ืฉื˜

ืคื•ืŸ ืึทืœืข ื“ืขื ืคืึทืจืฉื™ื™ื“ื ืงื™ื™ึทื˜, ื“ื™ ื‘ืจื™ืจื” ืื™ื– ื ืึธืš ื ื™ืฉื˜ ื’ืจื•ื™ืก. ื“ื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ืคึฟืŸ ืคืืจืœืื ื’ื˜: ื’ื•ื˜ ื–ื™ื›ืขืจื”ื™ื™ื˜, ืฉื˜ื™ืฆืŸ ืื•ื™ืฃ ืึทืœืข ื“ืขื•ื•ื™ืกืขืก (ื•ื•ื™ื ื“ืึธื•ื– 10, ืžืึทืงืึธืก, ืœื™ื ื•ืงืก, ืึทื ื“ืจื•ื™ื“, ื™ืึธืก) ืื•ืŸ, ืื™ืŸ ืคืึทืงื˜, ื“ื™ ืกื™ืžืคึผืœืขืจ ื“ื™ ื‘ืขืกืขืจ. ื“ืขืจื™ื‘ืขืจ, ื“ื™ ื‘ืจื™ืจื” ืื™ื– ื’ืขืคืืœืŸ ืื•ื™ืฃ EAP-TTLS ืื™ืŸ ืงืึทื ื“ื–ืฉืึทื ื’ืงืฉืึทืŸ ืžื™ื˜ ื“ื™ PAP ืคึผืจืึธื˜ืึธืงืึธืœ.
ื“ื™ ืงืฉื™ื ืงืขืŸ ืื•ื™ืคืฉื˜ื™ื™ืŸ - ืคืืจื•ื•ืืก ื ื•ืฆืŸ PAP? ื ืึธืš ืึทืœืข, ืขืก ื˜ืจืึทื ื–ืžื™ืฅ ืคึผืึทืกื•ื•ืขืจื“ื– ืื™ืŸ ืงืœืึธืจ ื˜ืขืงืกื˜?

ื™ื ื“ืืก ืื™ื– ื•ื•ืืจ. ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืฆื•ื•ื™ืฉืŸ FreeRadius ืื•ืŸ FreeIPA ื•ื•ืขื˜ ืคึผืึทืกื™ืจืŸ ืคึผื•ื ืงื˜ ื•ื•ื™ ื“ืึธืก. ืื™ืŸ ื“ื™ื‘ืึทื’ ืžืึธื“ืข, ืื™ืจ ืงืขื ืขืŸ ืฉืคึผื•ืจ ื•ื•ื™ ื“ื™ ื ืืžืขืŸ ืื•ืŸ ืคึผืึทืจืึธืœ ื–ืขื ืขืŸ ื’ืขืฉื™ืงื˜. ื™ืึธ, ืื•ืŸ ืœืึธื–ืŸ ื–ื™ื™ ื’ื™ื™ืŸ, ื ืึธืจ ืื™ืจ ื”ืึธื‘ืŸ ืึทืงืกืขืก ืฆื• ื“ื™ FreeRadius ืกืขืจื•ื•ืขืจ.

ืื™ืจ ืงืขื ื˜ ืœื™ื™ืขื ืขืŸ ืžืขืจ ื•ื•ืขื’ืŸ ื•ื•ื™ EAP-TTLS ืึทืจื‘ืขื˜ ื“ืึธ

FreeRADIUS

ืžื™ืจ ื•ื•ืขืœืŸ ืึทืคึผื’ืจื™ื™ื“ FreeRadius ืฆื• CentOS 7.6. ืขืก ืื™ื– ื’ืึธืจื ื™ืฉื˜ ืงืึธืžืคึผืœื™ืฆื™ืจื˜ ื“ืึธ, ืžื™ืจ ื™ื ืกื˜ืึทืœื™ืจืŸ ืขืก ืื™ืŸ ื“ื™ ื’ืขื•ื•ื™ื™ื ื˜ืœืขืš ื•ื•ืขื’.

yum install freeradius freeradius-utils freeradius-ldap -y

ืคื•ืŸ ื“ื™ ืคึผืึทืงืึทื“ื–ืฉืึทื–, ื•ื•ืขืจืกื™ืข 3.0.13 ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ. ื“ื™ ืœืขืฆื˜ืข ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื ื•ืžืขืŸ ื‘ื™ื™ึท https://freeradius.org/

ื ืึธืš ื“ืขื, FreeRadius ืื™ื– ืฉื•ื™ืŸ ืืจื‘ืขื˜ืŸ. ืื™ืจ ืงืขื ืขืŸ ื•ื ืงืึธืžืžืขื ื˜ ื“ื™ ืฉื•ืจื” ืื™ืŸ /etc/raddb/users

steve   Cleartext-Password := "testing"

ืงืึทื˜ืขืจ ืื™ืŸ ื“ื™ ืกืขืจื•ื•ืขืจ ืื™ืŸ ื“ื™ื‘ืึทื’ ืžืึธื“ืข

freeradius -X

ืื•ืŸ ืžืึทื›ืŸ ืึท ืคึผืจืึธื‘ืข ืงืฉืจ ืคึฟื•ืŸ ืœืึธืงืึทืœื”ืึธืกื˜

radtest steve testing 127.0.0.1 1812 testing123

ืžื™ืจ ื”ืื‘ืŸ ื‘ืืงื•ืžืขืŸ ืืŸ ืขื ื˜ืคืขืจ ื‘ืืงื•ืžืขืŸ ืึทืงืกืขืก - ืึธื ื ืขืžืขืŸ ืฉื™ื™ึทืŸ 115 ืคึฟื•ืŸ 127.0.0.1:1812 ืฆื• 127.0.0.1:56081 ืœืขื ื’ 20, ืขืก ืžื™ื˜ืœ ืึทืœืฅ ืื™ื– ื’ื•ื˜. ื’ื™ื™ ื•ื•ื™ื™ื˜ืขืจ.

ืงืึทื ืขืงื˜ื™ื ื’ ื“ื™ ืžืึธื“ื•ืœืข ldap.

ln -s /etc/raddb/mods-available/ldap /etc/raddb/mods-enabled/ldap

ืื•ืŸ ืžื™ืจ ื•ื•ืขืœืŸ ืขืก ืžื™ื“ ื˜ื•ื™ืฉืŸ. ืžื™ืจ ื“ืึทืจืคึฟืŸ FreeRadius ืฆื• ืงืขื ืขืŸ ืึทืงืกืขืก FreeIPA

ืžืึธื“ืก-ืขื ื™ื™ื‘ืึทืœื“/ืœื“ืึทืคึผ

ldap {
server="ldap://ldap.server.com"
port=636
start_tls=yes
identity="uid=admin,cn=users,dc=server,dc=com"
password=**********
base_dn="cn=users,dc=server,dc=com"
set_auth_type=yes
...
user {
base_dn="${..base_dn}"
filter="(uid=%{%{Stripped-User-Name}:-%{User-Name}})"
}
...

ืจื™ืกื˜ืึทืจื˜ ื“ื™ ืจืึทื“ื™ื•ืก ืกืขืจื•ื•ืขืจ ืื•ืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืกื™ื ื’ืงืจืึทื ืึทื–ื™ื™ืฉืึทืŸ ืคื•ืŸ LDAP ื ื™ืฆืขืจืก:

radtest user_ldap password_ldap localhost 1812 testing123

ืจืขื“ืึทื’ื™ืจืŸ ืขืึทืคึผ ืื™ืŸ ืžืึธื“ืก-ืขื ื™ื™ื‘ืึทืœื“ / ืขืึทืคึผ
ื“ืึธ ืžื™ืจ ื•ื•ืขืœืŸ ืœื™ื™ื’ืŸ ืฆื•ื•ื™ื™ ื™ื ืกื˜ืึทื ืกื™ื– ืคื•ืŸ ืขืึทืคึผ. ื–ื™ื™ ื–ืขื ืขืŸ ืึทื ื“ืขืจืฉ ื‘ืœื•ื™ื– ืื™ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืื•ืŸ ืฉืœื™ืกืœืขืŸ. ืื™ืš ื•ื•ืขื˜ ื“ืขืจืงืœืขืจืŸ ื•ื•ืึธืก ื“ืึธืก ืื™ื– ืืžืช ืื•ื ื˜ืŸ.

ืžืึธื“ืก-ืขื ื™ื™ื‘ืึทืœื“ / ืขืึทืคึผ

eap eap-client {                                                                                                                                                                                                                           default_eap_type = ttls                                                                                                                                                                                                                 timer_expire = 60                                                                                                                                                                                                                       ignore_unknown_eap_types = no                                                                                                                                                                                                          cisco_accounting_username_bug = no                                                                                                                                                                                                      max_sessions = ${max_requests}
           tls-config tls-common {
           private_key_file = ${certdir}/fisrt.key
           certificate_file = ${certdir}/first.crt
           dh_file = ${certdir}/dh
           ca_path = ${cadir}
           cipher_list = "HIGH"
           cipher_server_preference = no
           ecdh_curve = "prime256v1"
           check_crl = no
           }
                                                                                                                                                                                                                                                                                                                                                                                                                                                 
           ttls {
           tls = tls-common
           default_eap_type = md5
           copy_request_to_tunnel = no
           use_tunneled_reply = yes
           virtual_server = "inner-tunnel"
           }
}
eap eap-guest {
default_eap_type = ttls                                                                                                                                                                                                                 timer_expire = 60                                                                                                                                                                                                                       ignore_unknown_eap_types = no                                                                                                                                                                                                          cisco_accounting_username_bug = no                                                                                                                                                                                                      max_sessions = ${max_requests}
           tls-config tls-common {
           private_key_passwotd=blablabla
           private_key_file = ${certdir}/server.key
           certificate_file = ${certdir}/server.crt
           dh_file = ${certdir}/dh
           ca_path = ${cadir}
           cipher_list = "HIGH"
           cipher_server_preference = no
           ecdh_curve = "prime256v1"
           check_crl = no
           }
                                                                                                                                                                                                                                                                                                                                                                                                                                                 
           ttls {
           tls = tls-common
           default_eap_type = md5
           copy_request_to_tunnel = no
           use_tunneled_reply = yes
           virtual_server = "inner-tunnel"
           }
}

ื•ื•ื™ื™ึทื˜ืขืจ ืžื™ืจ ืจืขื“ืึทื’ื™ืจืŸ ืคึผืœืึทืฅ-ืขื ื™ื™ื‘ืึทืœื“ / ืคืขืœื™ืงื™ื™ึทื˜. ืื™ืš ื‘ื™ืŸ ืื™ื ื˜ืขืจืขืกื™ืจื˜ ืื™ืŸ ื“ืขืจ ืึธื˜ืขืจื™ื™ื– ืื•ืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ ืกืขืงืฉืึทื ื–.

ืคึผืœืึทืฅ-ืขื ื™ื™ื‘ืึทืœื“ / ืคืขืœื™ืงื™ื™ึทื˜

authorize {
  filter_username
  preprocess
  if (&User-Name == "guest") {
   eap-guest {
       ok = return
   }
  }
  elsif (&User-Name == "client") {
    eap-client {
       ok = return 
    }
  }
  else {
    eap-guest {
       ok = return
    }
  }
  ldap
  if ((ok || updated) && User-Password) {
    update {
        control:Auth-Type := ldap
    }
  }
  expiration
  logintime
  pap
  }

authenticate {
  Auth-Type LDAP {
    ldap
  }
  Auth-Type eap-guest {
    eap-guest
  }
  Auth-Type eap-client {
    eap-client
  }
  pap
}

ืื™ืŸ ื“ืขืจ ืึธื˜ืขืจื™ื™ื– ืึธืคึผื˜ื™ื™ืœื•ื ื’ ืžื™ืจ ื‘ืึทื–ื™ื™ึทื˜ื™ืงืŸ ืึทืœืข ืžืึทื“ื–ืฉื•ืœื– ื•ื•ืึธืก ืžื™ืจ ื˜ืึธืŸ ื ื™ื˜ ื“ืึทืจืคึฟืŸ. ืžื™ืจ ืœืึธื–ืŸ ื‘ืœื•ื™ื– ืœื“ืึทืคึผ. ืœื™ื™ื’ ืงืœื™ืขื ื˜ ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ื“ื•ืจืš ื ืืžืขืŸ. ื“ืึธืก ืื™ื– ื•ื•ืึธืก ืžื™ืจ ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื•ื•ื™ื™ ื™ื ืกื˜ืึทื ืกื™ื– ืคื•ืŸ ืขืึทืคึผ ืื•ื™ื‘ืŸ.

ืžื•ืœื˜ื™ ืขืึทืคึผื“ืขืจ ืคืึทืงื˜ ืื™ื– ืึทื– ื•ื•ืขืŸ ืงืึทื ืขืงื˜ื™ื ื’ ืขื˜ืœืขื›ืข ื“ืขื•ื•ื™ืกืขืก ืžื™ืจ ื•ื•ืขืœืŸ ื ื•ืฆืŸ ืกื™ืกื˜ืขื ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืื•ืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ืคืขืœื“. ืžื™ืจ ื”ืึธื‘ืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื•ืŸ ืฉืœื™ืกืœ ืคื•ืŸ ืึท ื˜ืจืึทืกื˜ื™ื“ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื•ื™ื˜ืึธืจื™ื˜ืขื˜. ืคึผืขืจืกื ืึทืœื™, ืื™ืŸ ืžื™ื™ืŸ ืžื™ื™ื ื•ื ื’, ื“ืขื ืงืฉืจ ืคึผืจืึธืฆืขื“ื•ืจ ืื™ื– ืกื™ืžืคึผืœืขืจ ื•ื•ื™ ืคืืจื•ื•ืืจืคืŸ ืึท ื–ื™ืš-ื’ืขื—ืชืžืขื˜ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื•ื™ืฃ ื™ืขื“ืขืจ ืžื™ื˜ืœ. ืื‘ืข ืจ ืืคื™ืœ ื• ื ืŸ ื–ืขืœื‘ืกื˜ึพื’ืขื—ืชื™ืžื˜ืข ืจ ืกืขืจื˜ื™ืคื™ืงืื˜ ืŸ ืื™ ื– ื ื ืš ื ื™ืฉ ื˜ ืžืขื’ืœืข ืš ื’ืขืฐืข ืŸ ืฆ ื• ืืฐืขืงื’ืฒืŸ . ืกืึทืžืกื•ื ื’ ื“ืขื•ื•ื™ืกืขืก ืื•ืŸ ืึทื ื“ืจื•ื™ื“ =<6 ื•ื•ืขืจืกื™ืขืก ืงืขื ืขืŸ ื ื™ืฉื˜ ื ื•ืฆืŸ ืกื™ืกื˜ืขื ืกืขืจื˜ื™ืคื™ืงืึทืฅ. ื“ืขืจื™ื‘ืขืจ, ืžื™ืจ ืžืึทื›ืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ื‘ื™ื™ึทืฉืคึผื™ืœ ืคื•ืŸ ืขืึทืคึผ-ื’ืึทืกื˜ ืคึฟืึทืจ ื–ื™ื™ ืžื™ื˜ ื–ื™ืš-ื’ืขื—ืชืžืขื˜ ืกืขืจื˜ื™ืคื™ืงืึทืฅ. ืคึฟืึทืจ ืึทืœืข ืื ื“ืขืจืข ื“ืขื•ื•ื™ืกืขืก ืžื™ืจ ื•ื•ืขืœืŸ ื ื•ืฆืŸ eap-client ืžื™ื˜ ืึท ื˜ืจืึทืกื˜ื™ื“ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ. ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ ืื™ื– ื‘ืืฉืœืืกืŸ ื“ื•ืจืš ื“ื™ ืึทื ืึธื ื™ืžืข ื‘ืึทื ื•ืฆืขืจืก ืคืขืœื“ ื•ื•ืขืŸ ืงืึทื ืขืงื˜ื™ื ื’ ื“ื™ ืžื™ื˜ืœ. ื‘ืœื•ื™ื– 3 ื•ื•ืึทืœื•ืขืก ื–ืขื ืขืŸ ืขืจืœื•ื™ื‘ื˜: ื’ืึทืกื˜, ืงืœื™ืขื ื˜ ืื•ืŸ ืึท ืœื™ื™ื“ื™ืง ืคืขืœื“. ื“ื™ ืžื ื•ื—ื” ืื™ื– ืึทืœืข ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ. ื“ืขื ืงืขื ืขืŸ ื–ื™ื™ืŸ ืงืึทื ืคื™ื’ื™ืขืจื“ ืื™ืŸ ืคึผืึทืœืึทืกื™ื–. ืื™ืš ื•ื•ืขืœ ื’ืขื‘ืŸ ืึท ื‘ื™ื™ึทืฉืคึผื™ืœ ืึท ื‘ื™ืกืœ ืฉืคึผืขื˜ืขืจ.

ื–ืืœ ืก ืจืขื“ืึทื’ื™ืจืŸ ื“ื™ ืึธื˜ืขืจื™ื™ื– ืื•ืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ ืกืขืงืฉืึทื ื– ืื™ืŸ ืคึผืœืึทืฅ-ืขื ื™ื™ื‘ืึทืœื“ / ื™ื ืขืจ-ื˜ื•ื ืขืœ

ืคึผืœืึทืฅ-ืขื ื™ื™ื‘ืึทืœื“ / ื™ื ืขืจ-ื˜ื•ื ืขืœ

authorize {
  filter_username
  filter_inner_identity
  update control {
   &Proxy-To-Realm := LOCAL
  }
  ldap
  if ((ok || updated) && User-Password) {
    update {
        control:Auth-Type := ldap
    }
  }
  expiration
  digest
  logintime
  pap
  }

authenticate {
  Auth-Type eap-guest {
    eap-guest
  }
  Auth-Type eap-client {
    eap-client
  }
  Auth-Type PAP {
    pap
  }
  ldap
}

ื•ื•ื™ื™ึทื˜ืขืจ, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืื™ืŸ ื“ื™ ืคึผืึทืœืึทืกื™ื– ื•ื•ืึธืก ื ืขืžืขืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืคึฟืึทืจ ืึทื ืึธื ื™ืžืข ื‘ืึทื ื•ืฆืขืจืก ืœืึธื’ื™ืŸ. ืขื“ื™ื˜ื™ื ื’ policy.d/filter.

ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื’ืขืคึฟื™ื ืขืŸ ืฉื•ืจื•ืช ืขื ืœืขืš ืฆื• ื“ืขื:

if (&outer.request:User-Name !~ /^(anon|@)/) {
  update request {
    Module-Failure-Message = "User-Name is not anonymized"
  }
  reject
}

ืื•ืŸ ืื•ื ื˜ืŸ ืื™ืŸ elsif ืœื™ื™ื’ ื“ื™ ื ื™ื™ื˜ื™ืง ื•ื•ืึทืœื•ืขืก:

elsif (&outer.request:User-Name !~ /^(guest|client|@)/) {
  update request {
    Module-Failure-Message = "User-Name is not anonymized"
  }
  reject
}

ืื™ืฆื˜ ืžื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืžืึทืš ืฆื• ื“ื™ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืกืขืจืฅ. ื“ืึธ ืžื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืฉื˜ืขืœืŸ ื“ื™ ืฉืœื™ืกืœ ืื•ืŸ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืคื•ืŸ ืึท ื˜ืจืึทืกื˜ื™ื“ ืกืขืจื˜ืึทืคืึทืงื™ื™ืฉืึทืŸ ืื•ื™ื˜ืึธืจื™ื˜ืขื˜, ื•ื•ืึธืก ืžื™ืจ ื”ืึธื‘ืŸ ืฉื•ื™ืŸ, ืื•ืŸ ืžื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื“ื–ืฉืขื ืขืจื™ื™ื˜ ื–ื™ืš-ื’ืขื—ืชืžืขื˜ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืคึฟืึทืจ ืขืึทืคึผ-ื’ืึทืกื˜.

ื˜ืฉืึทื ื’ื™ื ื’ ื“ื™ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืื™ืŸ ื“ืขืจ ื˜ืขืงืข ca.cnf.

ca.cnf


...
default_days = 3650
default_md = sha256
...
input_password = blablabla
output_password = blablabla
...
countryName = RU
stateOrProvinceNmae = State
localityNmae = City
organizationName = NONAME
emailAddress = [email protected]
commonName = "CA FreeRadius"

ืžื™ืจ ืฉืจื™ื™ึทื‘ืŸ ื“ื™ ื–ืขืœื‘ืข ื•ื•ืึทืœื•ืขืก ืื™ืŸ ื“ืขืจ ื˜ืขืงืข server.cnf. ืžื™ืจ ื ืึธืจ ื˜ื•ื™ืฉืŸ
commonName:

server.cnf


...
default_days = 3650
default_md = sha256
...
input_password = blablabla
output_password = blablabla
...
countryName = RU
stateOrProvinceNmae = State
localityNmae = City
organizationName = NONAME
emailAddress = [email protected]
commonName = "Server Certificate FreeRadius"

ืžื™ืจ ืฉืึทืคึฟืŸ:

make

ื’ืจื™ื™ื˜. ื‘ืืงื•ืžืขืŸ server.crt ะธ server.key ืžื™ืจ ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืจืขื’ื™ืกื˜ืจื™ืจื˜ ืื•ื™ื‘ืŸ ืื™ืŸ eap-guest.

ืื•ืŸ ืœืขืกืึธืฃ, ืœืึธื–ืŸ ืื•ื ื“ื– ืœื™ื™ื’ืŸ ืื•ื ื“ื–ืขืจ ืึทืงืกืขืก ืคื•ื ืงื˜ืŸ ืฆื• ื“ืขืจ ื˜ืขืงืข client.conf. ืื™ืš ื”ืึธื‘ืŸ 7 ืคื•ืŸ ื–ื™ื™ ืื™ืŸ ืกื“ืจ ื ื™ืฉื˜ ืฆื• ืœื™ื™ื’ืŸ ื™ืขื“ืขืจ ืคื•ื ื˜ ืกืขืคึผืขืจืึทื˜ืœื™, ืžื™ืจ ื•ื•ืขืœืŸ ืคืึทืจืฉืจื™ื™ึทื‘ืŸ ื‘ืœื•ื™ื– ื“ื™ ื ืขืฅ ืื™ืŸ ื•ื•ืึธืก ื–ื™ื™ ื–ืขื ืขืŸ ืœื™ื’ืŸ (ืžื™ื™ืŸ ืึทืงืกืขืก ืคื•ื ืงื˜ืŸ ื–ืขื ืขืŸ ืื™ืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ื•ื•ืœืึทืŸ).

client APs {
ipaddr = 192.168.100.0/24
password = password_AP
}

Ubiquiti ืงืึธื ื˜ืจืึธืœืœืขืจ

ืžื™ืจ ื›ืึทืคึผืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ื ืขืฅ ืื•ื™ืฃ ื“ื™ ืงืึธื ื˜ืจืึธืœืœืขืจ. ื–ืืœ ืขืก ื–ื™ื™ืŸ 192.168.2.0/24
ื’ื™ื™ืŸ ืฆื• ืกืขื˜ื˜ื™ื ื’ืก -> ืคึผืจืึธืคื™ืœ. ืœืึธืžื™ืจ ืฉืึทืคึฟืŸ ืึท ื ื™ื™ึทืข:

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ืžื™ืจ ืฉืจื™ื™ึทื‘ืŸ ื“ื™ ืึทื“ืจืขืก ืื•ืŸ ืคึผืึธืจื˜ ืคื•ืŸ ื“ื™ ืจืึทื“ื™ื•ืก ืกืขืจื•ื•ืขืจ ืื•ืŸ ื“ื™ ืคึผืึทืจืึธืœ ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ ื“ืขืจ ื˜ืขืงืข clients.conf:

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ืฉืึทืคึฟืŸ ืึท ื ื™ื™ึท ื•ื•ื™ื™ืจืœื™ืก ื ืขืฅ ื ืึธืžืขืŸ. ืกืขืœืขืงื˜ื™ืจืŸ WPA-EAP (ืขื ื˜ืขืจืคึผืจื™ื™ื–) ื•ื•ื™ ื“ื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ืคึฟืŸ ืื•ืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ื‘ืืฉืืคืŸ ืจืึทื“ื™ื•ืก ืคึผืจืึธืคื™ืœ:

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ืžื™ืจ ืจืึทื˜ืขื•ื•ืขืŸ ืึทืœืฅ, ืฆื•ืœื™ื™ื’ืŸ ืขืก ืื•ืŸ ื’ื™ื™ืŸ ืื•ื™ืฃ.

ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืงืœื™ื™ืึทื ืฅ

ื–ืืœ ืก ืึธื ื”ื™ื™ื‘ืŸ ืžื™ื˜ ื“ื™ ื›ืึทืจื“ืึทืกื˜ ื˜ื™ื™ืœ!

ืคึฟืขื ืฆื˜ืขืจ ืงืกื ื•ืžืงืก

ื“ื™ ืฉื•ื•ืขืจื™ืงื™ื™ื˜ ืงื•ืžื˜ ืึทืจืึธืคึผ ืฆื• ื“ื™ ืคืึทืงื˜ ืึทื– Windows ืงืขืŸ ื ื™ืฉื˜ ื ืึธืš ื•ื•ื™ืกืŸ ื•ื•ื™ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ืคึฟื™ืจืžืข WiFi ืื™ื‘ืขืจ ืึท ืคืขืœื“. ื“ืขืจื™ื‘ืขืจ, ืžื™ืจ ื”ืึธื‘ืŸ ืฆื• ืžืึทื ื™ื•ืึทืœื™ ื•ืคึผืœืึธืึทื“ ืื•ื ื“ื–ืขืจ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืฆื• ื“ื™ ื˜ืจืึทืกื˜ื™ื“ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืงืจืึธื. ื“ืึธ ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ืึท ื–ื™ืš-ื’ืขื—ืชืžืขื˜ ืื™ื™ื ืขืจ ืึธื“ืขืจ ืื™ื™ื ืขืจ ืคื•ืŸ ืึท ืกืขืจื˜ืึทืคืึทืงื™ื™ืฉืึทืŸ ืื•ื™ื˜ืึธืจื™ื˜ืขื˜. ืื™ืš ื•ื•ืขืœ ื ื•ืฆืŸ ื“ืขื ืฆื•ื•ื™ื™ื˜ืŸ.

ื•ื•ื™ื™ึทื˜ืขืจ ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืฉืึทืคึฟืŸ ืึท ื ื™ื™ึทืข ืงืฉืจ. ืฆื• ื˜ืึธืŸ ื“ืึธืก, ื’ื™ื™ืŸ ืฆื• ื ืขืฅ ืื•ืŸ ืื™ื ื˜ืขืจื ืขื˜ ืกืขื˜ื˜ื™ื ื’ืก -> ื ืขืฅ ืื•ืŸ ื™ื™ึทื ื˜ื™ื™ืœื•ื ื’ ืฆืขื ื˜ืขืจ -> ืฉืึทืคึฟืŸ ืื•ืŸ ืงืึทื ืคื™ื’ื™ืขืจ ืึท ื ื™ื™ึทืข ืงืฉืจ ืึธื“ืขืจ ื ืขืฅ:

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ืžื™ืจ ืžืึทื ื™ื•ืึทืœื™ ืึทืจื™ื™ึทืŸ ื“ื™ ื ืขืฅ ื ืึธืžืขืŸ ืื•ืŸ ื˜ื•ื™ืฉืŸ ื“ื™ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื˜ื™ืคึผ. ื“ืขืจื ืึธืš ื“ืจื™ืงื˜ ืื•ื™ืฃ ื˜ื•ื™ืฉืŸ ืงืฉืจ ืกืขื˜ื˜ื™ื ื’ืก ืื•ืŸ ืื™ืŸ ื“ื™ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืงื•ื•ื™ื˜ืœ, ืกืขืœืขืงื˜ื™ืจืŸ ื ืขืฅ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ - EAP-TTLS.

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ื’ื™ื™ืŸ ืฆื• ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก, ืฉื˜ืขืœืŸ ื“ื™ ืงืึทื ืคืึทื“ืขื ืฉื™ืึทืœืึทื˜ื™ ืคื•ืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ - ืงืœื™ืขื ื˜. ื•ื•ื™ ืึท ื˜ืจืึทืกื˜ื™ื“ ืกืขืจื˜ืึทืคืึทืงื™ื™ืฉืึทืŸ ืื•ื™ื˜ืึธืจื™ื˜ืขื˜, ืกืขืœืขืงื˜ื™ืจืŸ ื“ืขื ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืžื™ืจ ืฆื•ื’ืขื’ืขื‘ืŸ, ื˜ืฉืขืง ื“ื™ ืงืขืกื˜ืœ "ื“ื• ื–ืืœืกื˜ ื ื™ืฉื˜ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึท ืคืึทืจื‘ืขื˜ื•ื ื’ ืฆื• ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืื•ื™ื‘ ื“ืขืจ ืกืขืจื•ื•ืขืจ ืงืขืŸ ื ื™ืฉื˜ ื–ื™ื™ืŸ ืึธื˜ืขืจื™ื™ื–ื“" ืื•ืŸ ืกืขืœืขืงื˜ื™ืจืŸ ื“ืขื ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ืคึฟืŸ - ืงืœืึธืจ ื˜ืขืงืกื˜ ืคึผืึทืจืึธืœ (PAP).

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ื•ื•ื™ื™ึทื˜ืขืจ, ื’ื™ื™ืŸ ืฆื• ื ืึธืš ืคึผืึทืจืึทืžืขื˜ืขืจืก, ื˜ืฉืขืง ื“ื™ ืงืขืกื˜ืœ "ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืžืึธื“ืข." ืกืขืœืขืงื˜ื™ืจืŸ "User Authentication" ืื•ืŸ ื’ื™ื˜ ืื•ื™ืฃ ืจืึทื˜ืขื•ื•ืขืŸ ืงืจืึทื“ืขื ื˜ืฉืึทืœื–. ื“ืึธ ืื™ืจ ื•ื•ืขื˜ ื“ืึทืจืคึฟืŸ ืฆื• ืึทืจื™ื™ึทืŸ username_ldap ืื•ืŸ password_ldap

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ืžื™ืจ ืจืึทื˜ืขื•ื•ืขืŸ, ืฆื•ืœื™ื™ื’ืŸ, ื ืึธืขื ื˜ ืึทืœืฅ. ืื™ืจ ืงืขื ืขืŸ ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ืึท ื ื™ื™ึทืข ื ืขืฅ.

ืœื™ื ื•ืงืก

ืื™ืš ื˜ืขืกื˜ืขื“ ืื•ื™ืฃ Ubuntu 18.04, 18.10, Fedora 29, 30.

ืขืจืฉื˜ืขืจ, ืืจืืคืงืืคื™ืข ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืคึฟืึทืจ ื–ื™ืš. ืื™ืš ื”ืื‘ ื ื™ืฉื˜ ื’ืขืคื•ื ืขืŸ ืื™ืŸ ืœื™ื ื•ืงืก ืฆื™ ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ื ื•ืฆืŸ ืกื™ืกื˜ืขื ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืึธื“ืขืจ ืฆื™ ืขืก ืื™ื– ืึทื–ืึท ืึท ืงืจืึธื ืื™ืŸ ืึทืœืข.

ืžื™ืจ ื•ื•ืขืœืŸ ืคืึทืจื‘ื™ื ื“ืŸ ื“ื•ืจืš ืคืขืœื“. ื“ืขืจื™ื‘ืขืจ, ืžื™ืจ ื“ืึทืจืคึฟืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืคื•ืŸ ื“ื™ ืกืขืจื˜ืึทืคืึทืงื™ื™ืฉืึทืŸ ืื•ื™ื˜ืึธืจื™ื˜ืขื˜ ืคื•ืŸ ื•ื•ืึธืก ืื•ื ื“ื–ืขืจ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื™ื– ื’ืขืงื•ื™ืคื˜.

ืึทืœืข ืงืึทื ืขืงืฉืึทื ื– ื–ืขื ืขืŸ ื’ืขืžืื›ื˜ ืื™ืŸ ืื™ื™ืŸ ืคึฟืขื ืฆื˜ืขืจ. ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ืื•ื ื“ื–ืขืจ ื ืขืฅ:

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ืึทื ืึธื ื™ืžืข ื‘ืึทื ื•ืฆืขืจืก - ืงืœื™ืขื ื˜
domain - ื“ื™ ืคืขืœื“ ืคึฟืึทืจ ื•ื•ืึธืก ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื™ื– ืืจื•ื™ืก

ืึทื ื“ืจื•ื™ื“

ื ื™ื˜-ืกืึทืžืกื•ื ื’

ืคึฟื•ืŸ ื•ื•ืขืจืกื™ืข 7, ื•ื•ืขืŸ ืงืึทื ืขืงื˜ื™ื ื’ WiFi, ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ืกื™ืกื˜ืขื ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื“ื•ืจืš ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื‘ืœื•ื™ื– ื“ื™ ืคืขืœื“:

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

domain - ื“ื™ ืคืขืœื“ ืคึฟืึทืจ ื•ื•ืึธืก ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื™ื– ืืจื•ื™ืก
ืึทื ืึธื ื™ืžืข ื‘ืึทื ื•ืฆืขืจืก - ืงืœื™ืขื ื˜

ืกืึทืžืกื•ื ื’

ื•ื•ื™ ืื™ืš ื’ืขืฉืจื™ื‘ืŸ ืื•ื™ื‘ืŸ, ืกืึทืžืกื•ื ื’ ื“ืขื•ื•ื™ืกืขืก ื˜ืึธืŸ ื ื™ื˜ ื•ื•ื™ืกืŸ ื•ื•ื™ ืฆื• ื ื•ืฆืŸ ืกื™ืกื˜ืขื ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื•ื•ืขืŸ ืงืึทื ืขืงื˜ื™ื ื’ WiFi, ืื•ืŸ ื–ื™ื™ ื˜ืึธืŸ ื ื™ื˜ ื”ืึธื‘ืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ื“ื•ืจืš ืคืขืœื“. ื“ืขืจื™ื‘ืขืจ, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืžืึทื ื™ื•ืึทืœื™ ืœื™ื™ื’ืŸ ื“ื™ ื•ื•ืึธืจืฆืœ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืคื•ืŸ ื“ื™ ืกืขืจื˜ืึทืคืึทืงื™ื™ืฉืึทืŸ ืื•ื™ื˜ืึธืจื™ื˜ืขื˜ (ca.pem, ื ืขืžืขืŸ ืขืก ืคื•ืŸ ื“ื™ ืจืึทื“ื™ื•ืก ืกืขืจื•ื•ืขืจ). ื“ืึธืก ืื™ื– ื•ื•ื• ื–ื™ืš-ื’ืขื—ืชืžืขื˜ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜.

ืืจืืคืงืืคื™ืข ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืฆื• ื“ื™ื™ืŸ ืžื™ื˜ืœ ืื•ืŸ ื™ื ืกื˜ืึทืœื™ืจืŸ ืขืก.

ื™ื ืกื˜ืึธืœื™ื ื’ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸWiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ืื™ืŸ ื“ืขื ืคืึทืœ, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืฉื˜ืขืœืŸ ืึท ืคืึทืจืฉื˜ืขืœืŸ ื•ืคืฉืœื™ืกืŸ ืžื•ืกื˜ืขืจ, PIN ืงืึธื“ ืึธื“ืขืจ ืคึผืึทืจืึธืœ, ืื•ื™ื‘ ืขืก ืื™ื– ื ื™ืฉื˜ ืฉื•ื™ืŸ ื‘ืึทืฉื˜ื™ืžื˜:

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ืื™ืš ื’ืขื•ื•ื™ื–ืŸ ืึท ืงืึธืžืคึผืœืขืงืก ืึธืคึผืฆื™ืข ืคึฟืึทืจ ื™ื ืกื˜ืึธืœื™ื ื’ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ. ืื•ื™ืฃ ืจื•ื‘ึฟ ื“ืขื•ื•ื™ืกืขืก, ืคืฉื•ื˜ ื’ื™ื˜ ืื•ื™ืฃ ื“ื™ ื“ืึทื•ื ืœืึธื•ื“ื™ื“ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ.

ื•ื•ืขืŸ ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ, ืื™ืจ ืงืขื ืขืŸ ื’ื™ื™ื  ื•ื•ื™ื™ึทื˜ืขืจ ืฆื• ื“ื™ ืงืฉืจ:

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ื‘ืึทื•ื•ื™ื™ึทื–ืŸ - ืึธื ื•ื•ื™ื™ึทื–ืŸ ื“ื™ ื•ื•ืึธืก ืื™ืจ ื”ืึธื˜ ืื™ื ืกื˜ืึทืœื™ืจืŸ
ืึทื ืึธื ื™ืžืข ื‘ืึทื ื•ืฆืขืจืก - ื’ืึทืกื˜

ืžืึทืงืึธืก

ืขืคึผืœ ื“ืขื•ื•ื™ืกืขืก ืงืขื ืขืŸ ื‘ืœื•ื™ื– ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• EAP-TLS ืื•ื™ืก ืคื•ืŸ ื“ื™ ืงืขืกื˜ืœ, ืึธื‘ืขืจ ืื™ืจ ื ืึธืš ื“ืึทืจืคึฟืŸ ืฆื• ืฆื•ืฉื˜ืขืœืŸ ื–ื™ื™ ืžื™ื˜ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ. ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึท ืึทื ื“ืขืจืฉ ืงืฉืจ ืื•ืคึฟืŸ, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื ื•ืฆืŸ ืขืคึผืœ ืงืึธื ืคื™ื’ื•ืจืึทื˜ืึธืจ 2. ืึทืงืงืึธืจื“ื™ื ื’ืœื™, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืขืจืฉื˜ืขืจ ืืจืืคืงืืคื™ืข ืขืก ืฆื• ื“ื™ื™ืŸ ืžืขืง, ืฉืึทืคึฟืŸ ืึท ื ื™ื™ึทืข ืคึผืจืึธืคื™ืœ ืื•ืŸ ืœื™ื™ื’ืŸ ืึทืœืข ื“ื™ ื ื™ื™ื˜ื™ืง WiFi ืกืขื˜ื˜ื™ื ื’ืก.

ืขืคึผืœ ืงืึธื ืคื™ื’ื•ืจืึทื˜ืึธืจWiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ื“ืึธ ืžื™ืจ ืึธื ื•ื•ื™ื™ึทื–ืŸ ื“ืขื ื ืึธืžืขืŸ ืคื•ืŸ ืื•ื ื“ื–ืขืจ ื ืขืฅ
ื–ื™ื›ืขืจื”ื™ื™ื˜ ื˜ื™ืคึผ - WPA2 ืขื ื˜ืขืจืคึผืจื™ื™ื–
ืื ื’ืขื ื•ืžืขืŸ EAP ื˜ื™ื™ืคึผืก - TTLS
ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ ืื•ืŸ ืคึผืึทืจืึธืœ - ืœืึธื–ืŸ ืœื™ื™ื“ื™ืง
ื™ื ืขืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ - PAP
ื•ื™ืกื•ื•ื™ื™ื ื™ืงืกื˜ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ - ืงืœื™ืขื ื˜

Trust tab. ื“ืึธ ืžื™ืจ ืึธื ื•ื•ื™ื™ึทื–ืŸ ืื•ื ื“ื–ืขืจ ืคืขืœื“

ืึทืœืข. ื“ืขืจ ืคึผืจืึธืคื™ืœ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขืจืื˜ืขื•ื•ืขื˜, ื’ืขื—ืชืžืขื˜ ืื•ืŸ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืฆื• ื“ืขื•ื•ื™ืกืขืก

ื ืึธืš ื“ื™ ืคึผืจืึธืคื™ืœ ืื™ื– ื’ืจื™ื™ื˜, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืึธืคึผืœืึธื“ื™ืจืŸ ืขืก ืฆื• ื“ื™ื™ืŸ ืžืขืง ืื•ืŸ ื™ื ืกื˜ืึทืœื™ืจืŸ ืขืก. ื‘ืขืฉืึทืก ื“ื™ ื™ื™ึทื ืžืึธื ื˜ื™ืจื•ื ื’ ืคึผืจืึธืฆืขืก, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ usernmae_ldap ืื•ืŸ password_ldap ืคื•ืŸ ื“ื™ ื‘ืึทื ื™ืฆืขืจ:

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ื™ืึธืก

ื“ืขืจ ืคึผืจืึธืฆืขืก ืื™ื– ืขื ืœืขืš ืฆื• macOS. ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื ื•ืฆืŸ ืึท ืคึผืจืึธืคื™ืœ (ืื™ืจ ืงืขื ื˜ ื ื•ืฆืŸ ื“ื™ ื–ืขืœื‘ืข ืคึผืจืึธืคื™ืœ ื•ื•ื™ ืคึฟืึทืจ ืžืึทืงืึธืก. ื–ืขืŸ ืื•ื™ื‘ืŸ ืคึฟืึทืจ ื•ื•ื™ ืฆื• ืฉืึทืคึฟืŸ ืึท ืคึผืจืึธืคื™ืœ ืื™ืŸ ืขืคึผืœ ืงืึธื ืคื™ื’ื•ืจืึทื˜ืึธืจ).

ืืจืืคืงืืคื™ืข ื“ื™ ืคึผืจืึธืคื™ืœ, ื™ื ืกื˜ืึทืœื™ืจืŸ, ืึทืจื™ื™ึทืŸ ืงืจืึทื“ืขื ื˜ืฉืึทืœื–, ืคืึทืจื‘ื™ื ื“ืŸ:

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

WiFi ืขื ื˜ืขืจืคึผืจื™ื™ื–. FreeRadius + FreeIPA + Ubiquiti

ืึทื– ืก ืึทืœืข. ืžื™ืจ ืฉื˜ืขืœืŸ ืึทืจื•ื™ืฃ ื“ื™ ืจืึทื“ื™ื•ืก ืกืขืจื•ื•ืขืจ, ืกื™ื ืกืขื“ ืขืก ืžื™ื˜ FreeIPA ืื•ืŸ ื“ืขืจืฆื™ื™ืœื˜ ื“ื™ Ubiquiti ืึทืงืกืขืก ืคื•ื ืงื˜ืŸ ืฆื• ื ื•ืฆืŸ WPA2-EAP.

ืžืขื’ืœืขืš ืคืจืื’ืขืก

ืื™ืŸ: ื•ื•ื™ ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ ืึท ืคึผืจืึธืคื™ืœ / ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืฆื• ืึทืŸ ืึธื ื’ืขืฉื˜ืขืœื˜ืขืจ?

ื•ื•ืขื’ืŸ: ืื™ืš ืงืจืึธื ืึทืœืข ืกืขืจื˜ื™ืคื™ืงืึทืฅ / ืคึผืจืึธื•ืคื™ื™ืœื– ืื•ื™ืฃ ืคื˜ืคึผ ืžื™ื˜ ืึทืงืกืขืก ื“ื•ืจืš ื“ื™ ื•ื•ืขื‘. ืื™ืš ืฉื˜ืขืœืŸ ืึทืจื•ื™ืฃ ืึท ื’ืึทืกื˜ ื ืขืฅ ืžื™ื˜ ืึท ื’ื™ื›ืงื™ื™ึทื˜ ืฉื™ืขื•ืจ ืื•ืŸ ืึทืงืกืขืก ื‘ืœื•ื™ื– ืฆื• ื“ื™ ืื™ื ื˜ืขืจื ืขื˜, ืžื™ื˜ ื“ื™ ื•ื™ืกื ืขื ืคื•ืŸ ืคื˜ืคึผ.
ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืœืึทืกืฅ 2 ื˜ืขื’, ื ืึธืš ื•ื•ืึธืก ืขืก ืื™ื– ื‘ืึทืฉื˜ืขื˜ื™ืง ืื•ืŸ ื“ืขืจ ืงืœื™ืขื ื˜ ืื™ื– ืœื™ื ืงืก ืึธืŸ ื“ื™ ืื™ื ื˜ืขืจื ืขื˜. ืึทื–. ื•ื•ืขืŸ ืึทืŸ ืึธื ื’ืขืฉื˜ืขืœื˜ืขืจ ื•ื•ื™ืœ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• WiFi, ืขืจ ืขืจืฉื˜ืขืจ ืงืึทื ืขืงืฅ ืฆื• ื“ื™ ื’ืึทืกื˜ ื ืขืฅ, ืœืึธื’ืก ืื™ืŸ ืคื˜ืคึผ, ื“ืึทื•ื ืœืึธื•ื“ื– ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืึธื“ืขืจ ืคึผืจืึธืคื™ืœ ืขืจ ื“ืึทืจืฃ, ื™ื ืกื˜ืึธืœื– ื–ื™ื™, ืื•ืŸ ื“ืขืžืึธืœื˜ ืงืขื ืขืŸ ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ื“ื™ ืคึฟื™ืจืžืข ื ืขืฅ.

ืื™ืŸ: ืคืืจื•ื•ืืก ื ื™ืฉื˜ ื ื•ืฆืŸ ืึท ืกื›ืขืžืข ืžื™ื˜ MSCHAPv2? ืขืก ืื™ื– ื–ื™ื›ืขืจืขืจ!

ื•ื•ืขื’ืŸ: ืคื™ืจืกื˜ืœื™, ื“ืขื ืกื›ืขืžืข ืึทืจื‘ืขื˜ ื’ืขื–ื•ื ื˜ ืื•ื™ืฃ NPS (Windows Network Policy System), ืื™ืŸ ืื•ื ื“ื–ืขืจ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ, ืขืก ืื™ื– ืื•ื™ืš ื ื™ื™ื˜ื™ืง ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ LDAP (FreeIpa) ืื•ืŸ ืงืจืึธื ืคึผืึทืจืึธืœ ื”ืึทืฉืขืก ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ. ืœื™ื™ื’ ืฆื•. ืขืก ืื™ื– ื ื™ืฉื˜ ืงืขื“ื™ื™ึทื™ืง ืฆื• ืžืึทื›ืŸ ืกืขื˜ื˜ื™ื ื’ืก, ื•ื•ื™ื™ึทืœ ื“ืึธืก ืงืขืŸ ืคื™ืจืŸ ืฆื• ืคืึทืจืฉื™ื“ืŸ ืคึผืจืึธื‘ืœืขืžืก ืžื™ื˜ ืกื™ื ื’ืงืจืึทื ืึทื–ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ืึทืœื˜ืจืึทืกืึทื•ื ื“ ืกื™ืกื˜ืขื. ืฆื•ื•ื™ื™ื˜ื ืก, ื“ื™ ื”ืึทืฉ ืื™ื– MD4, ืึทื–ื•ื™ ืขืก ื˜ื•ื˜ ื ื™ืฉื˜ ืœื™ื™ื’ืŸ ืคื™ืœ ื–ื™ื›ืขืจื”ื™ื™ื˜

ืื™ืŸ: ืื™ื– ืขืก ืžืขื’ืœืขืš ืฆื• ื“ืขืจืœื•ื™ื‘ืŸ ื“ื™ื•ื•ื™ื™ืกืึทื– ืžื™ื˜ ืžืขืง ืึทื“ืจืขืกืขืก?

ื•ื•ืขื’ืŸ: ื ื™ื™ืŸ, ื“ืึธืก ืื™ื– ื ื™ืฉื˜ ื–ื™ื›ืขืจ, ืึทืŸ ืึทื˜ืึทืงืขืจ ืงืขื ืขืŸ ืคืึทืจืคื™ืจืŸ MAC ืึทื“ืจืขืกืขืก, ืื•ืŸ ืืคื™ืœื• ืžืขืจ, ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ื“ื•ืจืš MAC ืึทื“ืจืขืกืขืก ืื™ื– ื ื™ืฉื˜ ื’ืขืฉื˜ื™ืฆื˜ ืื•ื™ืฃ ืคื™ืœืข ื“ืขื•ื•ื™ืกืขืก

ืื™ืŸ: ืคืืจื•ื•ืืก ื ื•ืฆืŸ ืึทืœืข ื“ื™ ืกืขืจื˜ื™ืคื™ืงืึทืฅ? ืื™ืจ ืงืขื ืขืŸ ืคืึทืจื‘ื™ื ื“ืŸ ืึธืŸ ื–ื™ื™

ื•ื•ืขื’ืŸ: ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜ ืฆื• ื“ืขืจืœื•ื™ื‘ืŸ ื“ื™ ืกืขืจื•ื•ืขืจ. ื™ืขื ืข. ื•ื•ืขืŸ ืงืึทื ืขืงื˜ื™ื ื’, ื“ื™ ืžื™ื˜ืœ ื˜ืฉืขืงืก ืฆื™ ืขืก ืื™ื– ืึท ืกืขืจื•ื•ืขืจ ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื˜ืจืึทืกื˜ื™ื“ ืึธื“ืขืจ ื ื™ืฉื˜. ืื•ื™ื‘ ืึทื–ื•ื™, ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืœื™ื™ื–ื•ื ื’ ืื•ื™ื‘ ื ื™ื˜, ื“ื™ ืงืฉืจ ืื™ื– ืคืืจืžืื›ื˜. ืื™ืจ ืงืขื ืขืŸ ืคืึทืจื‘ื™ื ื“ืŸ ืึธืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ, ืึธื‘ืขืจ ืื•ื™ื‘ ืึท ืึทื˜ืึทืงืขืจ ืึธื“ืขืจ ื—ื‘ืจ ืฉื˜ืขืœืŸ ืึทืจื•ื™ืฃ ืึท ืจืึทื“ื™ื•ืก ืกืขืจื•ื•ืขืจ ืื•ืŸ ืึท ืึทืงืกืขืก ืคื•ื ื˜ ืžื™ื˜ ื“ื™ ื–ืขืœื‘ืข ื ืึธืžืขืŸ ื•ื•ื™ ืื•ื ื“ื–ืขืจ ืื™ืŸ ืฉื˜ื•ื‘, ืขืจ ืงืขื ืขืŸ ืœื™ื™ื›ื˜ ื™ื ื˜ืขืจืกืขืคึผื˜ ื“ื™ ื‘ืึทื ื™ืฆืขืจ ืก ืงืจืึทื“ืขื ื˜ืฉืึทืœื– (ื˜ืึธืŸ ื ื™ื˜ ืคืึทืจื’ืขืกืŸ ืึทื– ื–ื™ื™ ื–ืขื ืขืŸ ื˜ืจืึทื ืกืžื™ื˜ื˜ืขื“ ืื™ืŸ ืงืœืึธืจ ื˜ืขืงืกื˜) . ืื•ืŸ ื•ื•ืขืŸ ืึท ืกืขืจื˜ื™ืคื™ืงืึทื˜ ืื™ื– ื’ืขื ื™ืฆื˜, ื“ืขืจ ืคื™ื™ึทื ื˜ ื•ื•ืขื˜ ื–ืขืŸ ืื™ืŸ ื–ื™ื™ืŸ ืœืึธื’ืก ื‘ืœื•ื™ื– ืื•ื ื“ื–ืขืจ ืคื™ืงื˜ื™ื•ื•ืข ื‘ืึทื ื™ืฆืขืจ-ื ืึธืžืขืŸ - ื’ืึทืกื˜ ืึธื“ืขืจ ืงืœื™ืขื ื˜ ืื•ืŸ ืึท ื˜ื™ืคึผ ื˜ืขื•ืช - Unknown CA Certificate

ืึท ื‘ื™ืกืœ ืžืขืจ ื•ื•ืขื’ืŸ macOSื˜ื™ืคึผื™ืงืึทืœืœื™, ืื•ื™ืฃ macOS, ืจื™ื™ื ืกื˜ืึทืœ ื“ื™ ืกื™ืกื˜ืขื ืื™ื– ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ื“ื•ืจืš ื“ื™ ืื™ื ื˜ืขืจื ืขื˜. ืื™ืŸ ืึธืคึผื–ื•ืš ืžืึธื“ืข, ื“ื™ ืžืขืง ืžื•ื–ืŸ ื–ื™ื™ืŸ ืงืึธื ื ืขืงื˜ืขื“ ืฆื• WiFi, ืื•ืŸ ื ื™ื˜ ืื•ื ื“ื–ืขืจ ืคึฟื™ืจืžืข WiFi ืื•ืŸ ื ื™ื˜ ื“ื™ ื’ืึทืกื˜ ื ืขืฅ ื•ื•ืขื˜ ืึทืจื‘ืขื˜ืŸ ื“ืึธ. ืคึผืขืจืกื ืึทืœื™, ืื™ืš ืื™ื ืกื˜ืึทืœื™ืจืŸ ืืŸ ืื ื“ืขืจ ื ืขืฅ, ื“ื™ ื’ืขื•ื•ื™ื™ื ื˜ืœืขืš WPA2-PSK, ืคืึทืจื‘ืึธืจื’ืŸ, ื‘ืœื•ื™ื– ืคึฟืึทืจ ื˜ืขื›ื ื™ืฉ ืึทืคึผืขืจื™ื™ืฉืึทื ื–. ืึธื“ืขืจ ืื™ืจ ืงืขื ืขืŸ ืื•ื™ืš ืžืึทื›ืŸ ืึท ื‘ืึธืึธื˜ืึทื‘ืœืข ื•ืกื‘ ื‘ืœื™ืฅ ืคืึธืจ ืžื™ื˜ ื“ื™ ืกื™ืกื˜ืขื ืื™ืŸ ืฉื˜ื™ื™ึทื’ืŸ. ืึธื‘ืขืจ ืื•ื™ื‘ ื“ื™ื™ืŸ ืžืขืง ืื™ื– ื ืึธืš 2015, ืื™ืจ ื•ื•ืขื˜ ืื•ื™ืš ื“ืึทืจืคึฟืŸ ืฆื• ื’ืขืคึฟื™ื ืขืŸ ืึท ืึทื“ืึทืคึผื˜ืขืจ ืคึฟืึทืจ ื“ืขื ื‘ืœื™ืฅ ืคืึธืจ)

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’