The holy cow of servers.
Ranch is a socket acceptor pool for building awesome TCP and TLS servers
Check & print remote certificate
openssl s_client -connect <hostname>:<port> -showcerts
The web is moving to HTTPS, preventing network attackers from observing or injecting page contents. But HTTPS needs TLS certificates, and while deployment is increasingly a solved issue thanks to the ACME protocol and Let's Encrypt, development still mostly ends up happening over HTTP because no one can get an universally valid certificate for localhost.
SSLyze is a Python tool that can analyze the SSL configuration of a server by connecting to it. It is designed to be fast and comprehensive, and should help organizations and testers identify misconfigurations affecting their SSL servers.
Key features include:
- Multi-processed and multi-threaded scanning (it's fast)
- SSL 2.0/3.0 and TLS 1.0/1.1/1.2 compatibility
- Performance testing: session resumption and TLS tickets support
- Security testing: weak cipher suites, insecure renegotiation, CRIME, Heartbleed and more
- Server certificate validation and revocation checking through OCSP stapling
- Support for StartTLS handshakes on SMTP, XMPP, LDAP, POP, IMAP, RDP and FTP
- Support for client certificates when scanning servers that perform mutual authentication
- XML output to further process the scan results
- And much more !
apt-get install -t strech-backports python3-nacl
PyNaCl is a Python binding to libsodium, which is a fork of the Networking and Cryptography library. These libraries have a stated goal of improving usability, security and speed. It supports Python 2.7 and 3.4+ as well as PyPy 2.6+.
Features
Digital signatures
Secret-key encryption
Public-key encryption
Hashing and message authentication
Password based key derivation and password hashingWeave Net creates a virtual network that connects Docker containers across multiple hosts and enables their automatic discovery. With Weave Net, portable microservices-based applications consisting of multiple containers can run anywhere: on one host, multiple hosts or even across cloud providers and data centers. Applications use the network just as if the containers were all plugged into the same network switch, without having to configure port mappings, ambassadors or links.
Services provided by application containers on the weave network can be exposed to the outside world, regardless of where they are running. Similarly, existing internal systems can be opened to accept connections from application containers irrespective of their location.
s I plan to move from a proprietary calendaring to a more „ressource-aware” open source solution, I decided to give Radicale a try. It is open source, appears to be rather pragmatic in its approach to „standards” and has a small footprint in regards to system requirements.
With me running Debian 8 on my server, I decided to stick with the available package and not install „from source”. So a quick „apt-get install radicale” took care of installing the necessary software (do not forget to enable the Radicale daemon in /etc/default/radicale).
The configuration of Radicale is rather straightforward and simple. In regards to transport security, You can reuse an existing TLS certificate (or get a new one from Let’s encrypt). For authentication, you can choose between several options. As I don’t have an LDAP server (yet) and I didn’t want to create a .httpasswd entry for each user, I chose „IMAP”. So Radicale will validate all credentials against the local IMAP server (Dovecot in my case).
Every Kubernetes cluster has a cluster root Certificate Authority (CA). The CA is generally used by cluster components to validate the API server’s certificate, by the API server to validate kubelet client certificates, etc. To support this, the CA certificate bundle is distributed to every node in the cluster and is distributed as a secret attached to default service accounts. Optionally, your workloads can use this CA to establish trust. Your application can request a certificate signing using the certificates.k8s.io API using a protocol that is similar to the ACME draft.
In concept nxlog is similar to syslog-ng or rsyslog but it is not limited to unix and syslog only. It supports different platforms, log sources and formats so nxlog can be an ideal choice to implement a centralized logging system.
Centralize your Windows, Unix, Linux, BSD, Android and application logs on Windows, Unix, Linux, BSD, Android.
During the TLS interim meeting of last week (Oct 22 2014) I suggested that TLS
1.3 should abandon signature-based authentication (other than for certificates)
and be based solely on a combination of ephemeral Diffie-Hellman for PFS and
static Diffie-Hellman for authentication. This has multiple benefits including
major performance gain (by replacing the per-handshake RSA signature by the
server with a much cheaper elliptic curve exponentiation), compatibility with
the mechanisms required for forward secrecy, natural accommodation of a 0-RTT
option, and a simple extension without signatures for client authentication.
Below I present a schematic representation of the proposed protocol referred
to as OPTLS where OPT stands for OPTimized and/or for One-Point-Three.
The presentation is sketchy and omits the exact procedure for key derivation.
The latter is a crucial component for the security of the protocol, but
before getting into these details we want to get a sense of whether the WG is
interested in this approach. In the meantime, Hoeteck Wee and myself are
working on the details of the protocol and the security proof.
We describe a setting with optional 0-RTT and server-only authentication.
Client authentication can be added as a further option or as an extension
(similar to the current 1.3 proposal) - see below.
duraconf - A collection of hardened configuration files for SSL/TLS services
http://www.appelbaum.net/
Main features
This is a short but not exhaustive list of supported features on this beta version:
Powerful MCU (Multipoint Control Unit) for audio and video mixing
Stereoscopic (spatial) 3D and stereophonic audio
Full (1080p) and Ultra (2160p) HD video up to 120fps
Conference recording to a file (containers: .mp4, .avi, .mkv or .webm)
Revolutionary way to share presentations: documents are "streamed" in the video channel to allow any SIP client running on any device to participate
Smart adaptive audio and video bandwidth management
Congestion control mechanism
SIP registrar
4 SIP transports (WebSocket, TCP, TLS and UDP)
SA (direct connection to SIP clients) and AS (behind a server, such as Asterisk, reSIProcate, openSIPS, Kamailio…) modes
Support for any WebRTC-capable browser (WebRTC demo client at http://conf-call.org/)
Mixing different audio and video codecs on a single bridge (h264, vp8, h263, mp4v-es, theora, opus, g711, speex, g722, gsm, g729, amr, ilbc)
Protecting a bridge with PIN code
Unlimited number of bridges and participants
Connecting any SIP client (Mobiles, Tablets, Desktops, Set-top-boxes, Smart TVs...)
Easy interconnection with PSTN
NAT traversal (Symmetric RTP, RTCP-MUX, ICE, STUN and TURN)
RTCP Feedbacks (NACK, PLI, FIR, TMMBN, REMB…) for better video experience
Secure signalling (WSS, TLS) and media (SDES-SRTP and DTLS-SRTP)
Continuous presence
Smart algorithm to detect speakers and listeners
Different video patterns/layouts
Multiple operating systems (Linux, OS X, Windows …)
100% open source and free (no locked features)
Full documentation
…and many others