ื“ื™ OpenBSD ืคึผืจืึธื™ืขืงื˜ ื”ืื˜ ืืจื•ื™ืก OpenIKED 7.1, ืึท ืคึผืึธืจื˜ืึทื˜ื™ื•ื• ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ IKEv2 ืคึผืจืึธื˜ืึธืงืึธืœ ืคึฟืึทืจ IPsec

ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenIKED 7.1, ืึทืŸ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ IKEv2 ืคึผืจืึธื˜ืึธืงืึธืœ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื•ืจืš ื“ื™ OpenBSD ืคึผืจื•ื™ืขืงื˜, ืื™ื– ืืจื•ื™ืก. ื“ื™ IKEv2 ืงืึทืžืคึผืึธื•ื ืึทื ืฅ ื–ืขื ืขืŸ ืขืจื™ื“ื–ืฉื ืึทืœื™ ืึท ื™ื ื˜ืึทื’ืจืึทืœ ื˜ื™ื™ืœ ืคื•ืŸ ื“ื™ OpenBSD IPsec ืึธื ืœื™ื™ื’ืŸ, ืึธื‘ืขืจ ื–ืขื ืขืŸ ืื™ืฆื˜ ืืคื’ืขืฉื™ื™ื“ื˜ ืื™ืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืคึผืึธืจื˜ืึทื˜ื™ื•ื• ืคึผืขืงืœ ืื•ืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืื•ื™ืฃ ืื ื“ืขืจืข ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขืžืขืŸ. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, OpenIKED ืื™ื– ื˜ืขืกื˜ืขื“ ืื•ื™ืฃ FreeBSD, NetBSD, macOS ืื•ืŸ ืคืึทืจืฉื™ื“ืŸ ืœื™ื ื•ืงืก ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืึทืจื˜ืฉ, ื“ืขื‘ื™ืึทืŸ, ืคืขื“ืึธืจืึท ืื•ืŸ ื•ื‘ื•ื ื˜ื•. ื“ืขืจ ืงืึธื“ ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ C ืื•ืŸ ืื™ื– ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื•ื ื˜ืขืจ ื“ื™ ISC ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ.

OpenIKED ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืฆืขื•ื•ื™ืงืœืขืŸ IPsec-ื‘ืื–ื™ืจื˜ ื•ื•ื™ืจื˜ื•ืึทืœ ืคึผืจื™ื•ื•ืึทื˜ ื ืขื˜ื•ื•ืึธืจืงืก. ื“ื™ IPsec ืึธื ืœื™ื™ื’ืŸ ืื™ื– ืงืึทืžืคึผืจื™ื™ื–ื“ ืคื•ืŸ ืฆื•ื•ื™ื™ ื”ื•ื™ืคึผื˜ ืคึผืจืึธื˜ืึธืงืึธืœืก: ื“ื™ Key Exchange Protocol (IKE) ืื•ืŸ ื“ื™ Encrypted Transport Protocol (ESP). OpenIKED ื™ืžืคึผืœืึทืžืึทื ืฅ ืขืœืขืžืขื ื˜ืŸ ืคื•ืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ, ืฉืœื™ืกืœ ื•ื•ืขืงืกืœ ืื•ืŸ ื•ื™ืฉืึทืœื˜ ืคื•ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืึธืœื™ื˜ื™ืง, ืื•ืŸ ื“ืขืจ ืคึผืจืึธื˜ืึธืงืึธืœ ืคึฟืึทืจ ืขื ืงืจื™ืคึผื˜ื™ื ื’ ESP ืคืึทืจืงืขืจ ืื™ื– ื˜ื™ืคึผื™ืงืœื™ ืฆื•ื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš ื“ื™ ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขื ืงืขืจืŸ. ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืžืขื˜ื”ืึธื“ืก ืื™ืŸ OpenIKED ืงืขื ืขืŸ ื ื•ืฆืŸ ืคืึทืจ-ืฉืขืจื“ ืฉืœื™ืกืœืขืŸ, EAP MSCHAPv2 ืžื™ื˜ ืึทืŸ X.509 ื‘ืึทื•ื•ื™ื™ึทื–ืŸ, ืื•ืŸ RSA ืื•ืŸ ECDSA ืขืคื ื˜ืœืขืš ืฉืœื™ืกืœืขืŸ.

ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข ืžื•ืกื™ืฃ ื“ื™ 'ikectl show certinfo' ื‘ืึทืคึฟืขืœ ืฆื• ื•ื•ื™ื™ึทื–ืŸ ื“ืึทื•ื ืœืึธื•ื“ื™ื“ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืื•ืŸ ืกืขืจื˜ืึทืคืึทืงื™ื™ืฉืึทืŸ ืื•ื™ื˜ืืจื™ื˜ืขื˜ืŸ, ื™ืžืคึผืจื•ื•ื•ื– ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ IKEv2 ืึธื ื–ืึธื’ ืคืจืึทื’ืžืึทื ื˜ื™ื™ืฉืึทืŸ, ื™ืงืกืคึผืึทื ื“ื– ืคืึธื“ืขื ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื–, ืžื•ืกื™ืฃ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื”ื™ื ื˜ืขืจื’ืจื•ื ื˜ ืคึผืจืึธืฆืขืก ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ื ื™ืฆืŸ ื“ื™ ืึทืคึผืึทืจืžืึธืจ ืžืขืงืึทื ื™ื–ืึทื ืื™ืŸ ืœื™ื ื•ืงืก, ืžื•ืกื™ืฃ ื ื™ื™ึทืข ื˜ืขืกืฅ ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืจืึทื’ืจืขืฉืึทืŸ ืขื ื“ืขืจื•ื ื’ืขืŸ ืื•ื™ืฃ ืคืึทืจืฉื™ื“ืขื ืข ืคึผืœืึทื˜ืคืึธืจืžืก.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’