ñîâåðøåííî ñåêðåòíî ÐÎÌÀÍ ËÓÊÎÂÍÈÊΠ(LRB@SANDY.RU) Ñïåöâûïóñê: Õàêåð, íîìåð #072, ñòð. 072-010-6 Óñòàíàâëèâàåì óäîñòîâåðÿþùèé öåíòð: 1 ÂÛÁÈÐÀÅØÜ START–> SETTINGS–> CONTROL PANEL–> ADD/REMOVE PROGRAMS–> ADD/REMOVE WINDOWS COMPONENTS. 2 ÂÛÁÈÐÀÅØÜ ÊÎÌÏÎÍÅÍÒ CERTIFICATE SERVICES, ÄÀËÅÅ YES. 3 ÂÛÁÈÐÀÅØÜ STAND-ALONE ROOT CA, ÊËÈÊÀÅØÜ NEXT. 4 ÇÀÏÎËÍßÅØÜ ÏÎËÅ CA NAME (ÍÀÏÐÈÌÅÐ, TRUSTED ZONE), ÄÐÓÃÈÅ ÏÎËß - ÏÎ ÆÅËÀÍÈÞ, È ÍÀÆÈÌÀÅØÜ NEXT. 5 ÎÑÒÀÂËßÅØÜ ÂÑÅ ÏÓÒÈ ÏÎ ÓÌÎË×ÀÍÈÞ, ÍÀÆÈÌÀÅØÜ NEXT È OK. 6 ÏÎÑËÅ ÓÑÒÀÍÎÂÊÈ ÍÀÆÈÌÀÅØÜ FINISH. Óñòàíàâëèâàåòñÿ óäîñòîâåðÿþùèé öåíòð, êîíñîëü óïðàâëåíèÿ èì, è íàñòðàèâàåòñÿ ñàéò, ÷åðåç êîòîðûé êëèåíòû ìîãóò çàïðàøèâàòü è ïîëó÷àòü ñåðòèôèêàòû. Òåïåðü ñ ìàøèíû, íà êîòîðîé óñòàíîâëåí CA, äîëæåí îòêðûâàòüñÿ ñàéò http://127.0.0.1/certsrv/, à â Administrative Tools äîëæíà äîáàâèòüñÿ îñíàñòêà Certification Authority. Èòàê, äîïóñòèì, åñòü óñòàíîâëåííûé öåíòð ñ ip-àäðåñîì ip_öåíòð_ñåðò, òîãäà: 1 Ñ ÊÎÌÏÜÞÒÅÐÀ, ÍÀ ÊÎÒÎÐÎÌ ÒÐÅÁÓÅÒÑß ÓÑÒÀÍÎÂÈÒÜ ÑÅÐÒÈÔÈÊÀÒÛ,  ÀÄÐÅÑÍÎÉ ÑÒÐÎÊÅ ÍÀÁÈÐÀÅØÜ: HTTP://IP_ÖÅÍÒÐÀ_ÑÅÐÒ/CERTSRV. 2 ÂÛÁÈÐÀÅØÜ RETRIEVE THE CA CERTIFICATE OR CERTIFICATE REVOCATION LIST, ÆÌÅØÜ NEXT. 3 ÍÀÆÈÌÀÅØÜ ÍÀ ÑÑÛËÊÓ DOWNLOAD CA CERTIFICATE È ÂÛÁÈÐÀÅØÜ SAVE. 4 ÑÎÕÐÀÍßÅØÜ ÔÀÉË, ÑÎÄÅÐÆÀÙÈÉ ÑÅÐÒÈÔÈÊÀÒ, ÍÀ ÄÈÑÊ. 5 ÌÅÍÞ START–> RUN–> MMC, ÍÀÆÈÌÀÅØÜ ENTER. 6.  ÎÊÍÅ ÂÛÁÈÐÀÅØÜ FILE..., ÄÀËÅÅ ADD/REMOVE SNAP-IN, ÒÀÌ ADD... 7.  ÑÏÈÑÊÅ ÂÛÁÈÐÀÅØÜ CERTIFICATES, ÍÀÆÈÌÀÅØÜ ADD..., ÂÛÁÈÐÀÅØÜ COMPUTER ACCOUNT È NEXT. 8. ÎÑÒÀÂËßÅØÜ LOCAL COMPUTER, ÄÀËÅÅ FINISH È ÇÀÊÐÛÂÀÅØÜ ËÈØÍÈÅ ÎÊÍÀ. 9. ÎÒÊÐÛÂÀÅØÜ ÄÅÐÅÂÎ CERTIFICATES, ÊËÈÊÀß ÍÀ ÏËÞÑ,  ÏÎÄÄÅÐÅÂÅ ÎÒÊÐÛÂÀÅØÜ TRUSTED ROOT CERTIFICATION AUTHORITIES È ÏÐÀÂÛÉ ÊËÈÊ ÍÀ CERTIFICATES. 10.  ÊÎÍÒÅÊÑÒÍÎÌ ÌÅÍÞ ÂÛÁÈÐÀÅØÜ ALL TASKS..., ÄÀËÅÅ IMPORT. 11.  ÌÀÑÒÅÐÅ ÍÀÆÈÌÀÅØÜ NEXT,  ÑËÅÄÓÞÙÅÌ ÎÊÍÅ — BROWSE... È ÍÀÕÎÄÈØÜ ÔÀÉË, ÏÎËÓ×ÅÍÍÛÉ Ñ ÍÀØÅÃÎ ÖÑ ÑÅÐÒÈÔÈÊÀÒÀ, ÆÌÅØÜ NEXT. 12. ÄÀËÅÅ NEXT, ÎÏßÒÜ NEXT È FINISH. 13. ÍÀÆÈÌÀÅØÜ OK  ÎÊÎØÊÅ, ÓÂÅÄÎÌËßÞÙÅÌ ÎÁ ÓÑÏÅØÍÎÌ ÈÌÏÎÐÒÅ. Ñîõðàíÿåøü êîíñîëü ñ îñíàñòêîé ñåðòèôèêàòîâ, îíà åùå ïðèãîäèòñÿ. Òåïåðü â ñïèñêå äîâåðåííûõ ó íàñ åñòü ñåðòèôèêàò ñîçäàííîãî íàìè óäîñòîâåðÿþùåãî öåíòðà, è ìîæíî óêàçàòü, ÷òî äëÿ àóòåíòèôèêàöèè êîíöîâ òóííåëÿ IPSec ìîæíî èñïîëüçîâàòü ñåðòèôèêàòû, âûäàííûå ýòèì öåíòðîì. Ñäåëàåì ýòî: 1 ÌÅÍÞ START, ÄÀËÅÅ RUN, ÍÀÁÈÐÀÅØÜ SECPOL.MSC, ÍÀÆÈÌÀÅØÜ ENTER. 2 ÑËÅÂÀ ÂÛÁÈÐÀÅØÜ IPSEC POLICIES ON LOCAL MACHINE. 3  ÏÐÀÂÎÉ ÏÀÍÅËÈ ÄÂÎÉÍÎÉ ÊËÈÊ ÍÀ ÍÀØÅÉ ÏÎËÈÒÈÊÅ IPSEC (IPSEC NETA=>NETB). 4 ÄÀËÅÅ ÄÂÎÉÍÎÉ ÊËÈÊ ÍÀ ÏÅÐÂÎÌ ÔÈËÜÒÐÅ (NETA=>NETB), ÇÀÊËÀÄÊÀ AUTHENTICATION METHOD, ÄÀËÅÅ ADD... 5 ÂÛÁÈÐÀÅØÜ USE A CERTIFICATE FROM THIS CERTIFICATE AUTHORITY (CA), ÍÀÆÈÌÀÅØÜ BROWSE... 6  ÑÏÈÑÊÅ ÂÛÁÈÐÀÅØÜ ÂÍÎÂÜ ÑÎÇÄÀÍÍÛÉ ÓÄÎÑÒÎÂÅÐßÞÙÈÉ ÖÅÍÒÐ È ÍÀÆÈÌÀÅØÜ OK. 7  ÑËÅÄÓÞÙÅÌ ÎÊÎØÊÅ OK. 8 ÄËß ×ÈÑÒÎÒÛ ÝÊÑÏÅÐÈÌÅÍÒÀ ÓÄÀËÈ ÂÑÅ ÎÑÒÀËÜÍÛÅ ÌÅÒÎÄÛ ÀÓÒÅÍÒÈÔÈÊÀÖÈÈ, ÏÎÌÅ×Àß ÊÀÆÄÛÉ ÈÇ ÍÈÕ È ÍÀÆÈÌÀß REMOVE È YES  ÏÎßÂÈÂØÅÌÑß ÎÊÍÅ. 9 ÏÎÂÒÎÐßÅØÜ ÝÒÓ ÏÐÎÖÅÄÓÐÓ ÄËß ÂÒÎÐÎÃÎ ÔÈËÜÒÐÀ (NETB=>NETA). |