Applied Crypto Hardening
Total Page:16
File Type:pdf, Size:1020Kb
Applied Crypto Hardening Wolfgang Breyha, David Durvaux, Tobias Dussa, L. Aaron Kaplan, Florian Mendel, Christian Mock, Manuel Koschuch, Adi Kriegisch, Ulrich Pöschl, Ramin Sabet, Berg San, Ralf Schlatterbeck, Thomas Schreck, Alexander Würstlein, Aaron Zauner, Pepi Zawodsky (University of Vienna, CERT.be, KIT-CERT, CERT.at, A-SIT/IAIK, coretec.at,FH Campus Wien, VRVis, MilCERT Austria, A-Trust, Runtux.com,Friedrich-Alexander University Erlangen-Nuremberg, azet.org, maclemon.at) April 25, 2017 Contents 1. Abstract 5 1.1. Acknowledgements ........................................ 6 2. Introduction 8 2.1. Audience .............................................. 8 2.2. Related publications ........................................ 8 2.3. How to read this guide ....................................... 8 2.4. Disclaimer and scope ........................................ 9 2.4.1. Scope ............................................ 10 2.5. Methods ............................................... 11 3. Practical recommendations 12 3.1. Webservers ............................................. 12 3.1.1. Apache ........................................... 12 3.1.2. lighttpd ........................................... 13 3.1.3. nginx ............................................ 14 3.1.4. Cherokee .......................................... 15 3.1.5. MS IIS ............................................ 17 3.2. SSH ................................................. 20 3.2.1. OpenSSH .......................................... 20 3.2.2. Cisco ASA .......................................... 21 3.2.3. Cisco IOS .......................................... 22 3.3. Mail Servers ............................................. 23 3.3.1. TLS usage in mail server protocols ............................ 23 3.3.2. Recommended configuration ............................... 23 3.3.3. Dovecot ........................................... 24 3.3.4. cyrus-imapd ........................................ 25 3.3.5. Postfix ........................................... 26 3.3.6. Exim ............................................ 28 3.3.7. Cisco ESA/IronPort ..................................... 30 3.4. VPNs ................................................. 33 3.4.1. IPsec ............................................ 33 3.4.2. Check Point FireWall-1 ................................... 35 3.4.3. OpenVPN .......................................... 38 3.4.4. PPTP ............................................ 40 3.4.5. Cisco ASA .......................................... 40 3.4.6. Openswan ......................................... 42 3.4.7. tinc ............................................. 43 3.5. PGP/GPG - Pretty Good Privacy .................................. 44 3.5.1. Hashing ........................................... 44 3.6. IPMI, ILO and other lights out management solutions ...................... 45 3.7. Instant Messaging Systems ..................................... 45 3.7.1. General server configuration recommendations ..................... 45 3.7.2. ejabberd .......................................... 45 Applied Crypto Hardening page 2 of 103 Contents Contents 3.7.3. Chat privacy - Off-the-Record Messaging (OTR) ...................... 47 3.7.4. Charybdis .......................................... 47 3.7.5. SILC ............................................. 47 3.8. Database Systems ......................................... 48 3.8.1. Oracle ............................................ 48 3.8.2. MySQL ........................................... 48 3.8.3. DB2 ............................................. 49 3.8.4. PostgreSQL ......................................... 49 3.9. Intercepting proxy solutions and reverse proxies ......................... 50 3.9.1. Bluecoat .......................................... 51 3.9.2. HAProxy .......................................... 52 3.9.3. Pound ............................................ 53 3.9.4. stunnel ........................................... 53 3.10. Kerberos .............................................. 54 3.10.1. Overview .......................................... 54 3.10.2. Implementations ...................................... 56 4. Theory 60 4.1. Overview .............................................. 60 4.2. Cipher suites ............................................ 60 4.2.1. Architectural overview ................................... 60 4.2.2. Forward Secrecy ...................................... 61 4.2.3. Recommended cipher suites ............................... 62 4.2.4. Compatibility: ....................................... 62 4.2.5. Compatibility: ....................................... 64 4.2.6. Explanation: ........................................ 64 4.2.7. Insecure Ciphers ...................................... 64 4.2.8. Compatibility ........................................ 65 4.2.9. Choosing your own cipher suites ............................. 65 4.3. Random Number Generators ................................... 67 4.3.1. When random number generators fail .......................... 67 4.3.2. Linux ............................................ 68 4.3.3. Recommendations ..................................... 68 4.4. Keylengths ............................................. 69 4.4.1. Summary .......................................... 70 4.4.2. Special remark on 3DES: .................................. 70 4.5. A note on Elliptic Curve Cryptography ............................... 71 4.6. A note on SHA-1 ........................................... 71 4.7. A note on Diffie Hellman Key Exchanges .............................. 72 4.8. Public Key Infrastructures ..................................... 72 4.8.1. Certificate Authorities ................................... 72 4.8.2. Hardening PKI ....................................... 74 4.8.3. Certification Authorization Records ............................ 74 4.9. TLS and its support mechanisms ................................. 76 4.9.1. HTTP Strict Transport Security (HSTS) .......................... 76 4.9.2. HTTP Public Key Pinning (HPKP) ............................. 78 A. Tools 82 A.1. SSL & TLS .............................................. 82 A.2. Key length .............................................. 83 A.3. RNGs ................................................ 83 A.4. Guides ................................................ 84 Applied Crypto Hardening page 3 of 103 Contents Contents B. Links 85 C. Suggested Reading 87 D. SSL libraries 88 D.1. Priority strings ........................................... 88 E. Cipher Suite Name Cross-Reference 89 F. Further research 96 F.1. Software not covered by this guide ................................ 97 G. Acknowledgements 98 H. Glossary 99 Applied Crypto Hardening page 4 of 103 1. Abstract This guide arose out of the need for system administrators to have an updated, solid, well researched and thought-through guide for configuring SSL, PGP, SSH and other cryptographic tools in the post-Snowden age. Triggered by the NSA leaks in the summer of 2013, many system administrators and IT security officers saw the need to strengthen their encryption settings. This guide is specifically written for these system administra- tors. As Schneier noted in , it seems that intelligence agencies and adversaries on the Internet are not breaking so much the mathematics of encryption per se, but rather use software and hardware weaknesses, subvert standardization processes, plant backdoors, rig random number generators and most of all exploit careless settings in server configurations and encryption systems to listen in on private communications. Worst of all, most communication on the internet is not encrypted at all by default (for SMTP, opportunistic TLS would be a solution). This guide can only address one aspect of securing our information systems: getting the crypto settings right to the best of the authors’ current knowledge. Other attacks, as the above mentioned, require different protection schemes which are not covered in this guide. This guide is not an introduction to cryptography. For background information on cryptography and cryptoanalysis we would like to refer the reader to the references in appendix [cha:links] and [cha:suggested-reading] at the end of this document. The focus of this guide is merely to give current best practices for configuring complex cipher suites and related parameters in a copy & paste-able manner. The guide tries to stay as concise as is possible for such a complex topic as cryptography. Naturally, it can not be complete. There are many excellent guides and best practice documents available when it comes to cryptography. However none of them focuses specifically on what an average system administrator needs for hardening his or her systems’ crypto settings. This guide tries to fill this gap. Applied Crypto Hardening page 5 of 103 1.1. Acknowledgements 1.1. Acknowledgements Do not talk unencrypted 1.1. Acknowledgements We would like to express our thanks to the following reviewers and people who have generously offered their time and interest (in alphabetical order): Applied Crypto Hardening page 6 of 103 1.1. Acknowledgements 1.1. Acknowledgements • Brown, Scott • Brulebois, Cyril • Dirksen-Thedens, Mathis • Dulaunoy, Alexandre • Gühring Philipp • Grigg, Ian • Haslinger, Gunnar • Huebl, Axel • Kovacic, Daniel • Lenzhofer, Stefan • Lorünser, Thomas • Maass, Max • Mehlmauer, Christian • Millauer, Tobias • Mirbach, Andreas • O’Brien, Hugh • Pacher, Christoph • Palfrader, Peter • Pape, Tobias (layout) • Petukhova,