<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Slightly less Random Ramblings</title>
	
	<link>http://robwicks.wordpress.com</link>
	<description>Collected rants from a random guy on the Internet</description>
	<lastBuildDate>Thu, 19 Jan 2012 04:13:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain="robwicks.wordpress.com" port="80" path="/?rsscloud=notify" registerProcedure="" protocol="http-post" />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Slightly less Random Ramblings</title>
		<link>http://robwicks.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://robwicks.wordpress.com/osd.xml" title="Slightly less Random Ramblings" />
	
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/RobWickssRandomRamblings" /><feedburner:info uri="robwickssrandomramblings" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://robwicks.wordpress.com/?pushpress=hub" /><item>
		<title>Thank you Asus!</title>
		<link>http://feedproxy.google.com/~r/RobWickssRandomRamblings/~3/uZkWryl-Gcc/</link>
		<comments>http://robwicks.wordpress.com/2012/01/10/thank-you-asus/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 11:56:37 +0000</pubDate>
		<dc:creator>Robert Wicks</dc:creator>
				<category><![CDATA[encryption]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Truecrypt]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[AES]]></category>
		<category><![CDATA[AES-NI]]></category>
		<category><![CDATA[Asus]]></category>
		<category><![CDATA[BIOS]]></category>
		<category><![CDATA[CPU]]></category>
		<category><![CDATA[Intel]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[truecrypt]]></category>

		<guid isPermaLink="false">https://robwicks.wordpress.com/?p=166</guid>
		<description><![CDATA[I bought an Asus U56E from Fry’s, which has an Intel i5-2410M CPU. The laptop has been very good, having excellent battery life and good performance. I replaced the internal optical drive with a drive caddy so that I could replace the internal drive with an SSD, but have an additional spinning drive in order [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=166&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I bought an <a href="http://www.frys.com/product/6755055" target="_blank">Asus U56E from Fry’s</a>, which has an <a href="http://ark.intel.com/products/52224" target="_blank">Intel i5-2410M CPU</a>. The laptop has been very good, having excellent battery life and good performance. I replaced the internal optical drive with a drive caddy so that I could replace the internal drive with an SSD, but have an additional spinning drive in order to have a larger amount of space. My SSD has built-in encryption, however the spinning drive does not. I use Truecrypt. I wanted the i5 because I was under the mistaken impression that they all supported <a href="http://software.intel.com/en-us/articles/intel-advanced-encryption-standard-instructions-aes-ni/" target="_blank">AES-NI</a>. I later discovered that Intel has issued a microcode update for this CPU which enables the feature, but the BIOS manufacturer needed to enable it in the system BIOS. Asus has now enabled this feature in version 213 of the BIOS. Truecrypt’s benchmark performance has increased 5x since the update.</p>
<br />Filed under: <a href='http://robwicks.wordpress.com/category/encryption/'>encryption</a>, <a href='http://robwicks.wordpress.com/category/security/'>security</a>, <a href='http://robwicks.wordpress.com/category/truecrypt/'>Truecrypt</a>, <a href='http://robwicks.wordpress.com/category/windows/'>Windows</a> Tagged: <a href='http://robwicks.wordpress.com/tag/aes/'>AES</a>, <a href='http://robwicks.wordpress.com/tag/aes-ni/'>AES-NI</a>, <a href='http://robwicks.wordpress.com/tag/asus/'>Asus</a>, <a href='http://robwicks.wordpress.com/tag/bios/'>BIOS</a>, <a href='http://robwicks.wordpress.com/tag/cpu/'>CPU</a>, <a href='http://robwicks.wordpress.com/tag/encryption/'>encryption</a>, <a href='http://robwicks.wordpress.com/tag/intel/'>Intel</a>, <a href='http://robwicks.wordpress.com/tag/laptop/'>laptop</a>, <a href='http://robwicks.wordpress.com/tag/truecrypt-2/'>truecrypt</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/robwicks.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/robwicks.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/robwicks.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/robwicks.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/robwicks.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/robwicks.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/robwicks.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/robwicks.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/robwicks.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/robwicks.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/robwicks.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/robwicks.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/robwicks.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/robwicks.wordpress.com/166/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=166&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" /><img src="http://feeds.feedburner.com/~r/RobWickssRandomRamblings/~4/uZkWryl-Gcc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://robwicks.wordpress.com/2012/01/10/thank-you-asus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bbe1b95054377e4b32b421c957748a2c?s=96&amp;d=identicon&amp;r=G" medium="image">
			<media:title type="html">robwicks</media:title>
		</media:content>
	<feedburner:origLink>http://robwicks.wordpress.com/2012/01/10/thank-you-asus/</feedburner:origLink></item>
		<item>
		<title>Curious Key Corruption</title>
		<link>http://feedproxy.google.com/~r/RobWickssRandomRamblings/~3/YxUc0XqQMgA/</link>
		<comments>http://robwicks.wordpress.com/2011/12/04/curious-key-corruption/#comments</comments>
		<pubDate>Sun, 04 Dec 2011 17:02:11 +0000</pubDate>
		<dc:creator>Robert Wicks</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[certificates]]></category>
		<category><![CDATA[IPSec]]></category>
		<category><![CDATA[OpenSSL]]></category>
		<category><![CDATA[OpenVPN]]></category>
		<category><![CDATA[OpenWrt]]></category>
		<category><![CDATA[pkcs12]]></category>
		<category><![CDATA[Strongswan]]></category>
		<category><![CDATA[VPN]]></category>

		<guid isPermaLink="false">http://robwicks.wordpress.com/?p=158</guid>
		<description><![CDATA[I used the easy-rsa script to generate some new server certs recently, and found that my strongswan install on OpenWRT could not load the RSA key. This despite the fact that the same key works fine in OpenVPN on the same server. The interesting thing is that when I use the build-key-pkcs12 script instead of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=158&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I used the easy-rsa script to generate some new server certs recently, and found that my strongswan install on OpenWRT could not load the RSA key. This despite the fact that the same key works fine in OpenVPN on the same server. The interesting thing is that when I use the build-key-pkcs12 script instead of the build-key-server script, and then use openssl on the router to extract the cert and key, the key works. it is also a different size. The key kept coming up as 1704 bytes when using the server script, but 1669 bytes with the pkcs12 script. Since the pkcs12 script works, I suggest using it always. It generates the key and crt files any way, even though the extracted key file was a different size than the generated one with the same set of files. There must be a bug somewhere.</p>
<br />Filed under: <a href='http://robwicks.wordpress.com/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://robwicks.wordpress.com/tag/certificates/'>certificates</a>, <a href='http://robwicks.wordpress.com/tag/ipsec/'>IPSec</a>, <a href='http://robwicks.wordpress.com/tag/openssl/'>OpenSSL</a>, <a href='http://robwicks.wordpress.com/tag/openvpn/'>OpenVPN</a>, <a href='http://robwicks.wordpress.com/tag/openwrt-2/'>OpenWrt</a>, <a href='http://robwicks.wordpress.com/tag/pkcs12/'>pkcs12</a>, <a href='http://robwicks.wordpress.com/tag/strongswan/'>Strongswan</a>, <a href='http://robwicks.wordpress.com/tag/vpn/'>VPN</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/robwicks.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/robwicks.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/robwicks.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/robwicks.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/robwicks.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/robwicks.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/robwicks.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/robwicks.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/robwicks.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/robwicks.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/robwicks.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/robwicks.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/robwicks.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/robwicks.wordpress.com/158/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=158&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" /><img src="http://feeds.feedburner.com/~r/RobWickssRandomRamblings/~4/YxUc0XqQMgA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://robwicks.wordpress.com/2011/12/04/curious-key-corruption/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bbe1b95054377e4b32b421c957748a2c?s=96&amp;d=identicon&amp;r=G" medium="image">
			<media:title type="html">robwicks</media:title>
		</media:content>
	<feedburner:origLink>http://robwicks.wordpress.com/2011/12/04/curious-key-corruption/</feedburner:origLink></item>
		<item>
		<title>Strongswan 4.5.1 now in the OpenWRT Trunk</title>
		<link>http://feedproxy.google.com/~r/RobWickssRandomRamblings/~3/a44MAuFYlYI/</link>
		<comments>http://robwicks.wordpress.com/2011/05/23/strongswan-4-5-1-now-in-the-openwrt-trunk/#comments</comments>
		<pubDate>Mon, 23 May 2011 23:49:26 +0000</pubDate>
		<dc:creator>Robert Wicks</dc:creator>
				<category><![CDATA[encryption]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[OpenWRT]]></category>
		<category><![CDATA[OpenWrt]]></category>
		<category><![CDATA[Router]]></category>
		<category><![CDATA[Strongswan]]></category>

		<guid isPermaLink="false">http://robwicks.wordpress.com/?p=154</guid>
		<description><![CDATA[My issues with Strongswan in the OpenWRT trunk are now resolved. Strongswan 4.5.1-1 is available. Filed under: encryption, linux, OpenWRT Tagged: linux, OpenWrt, Router, Strongswan<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=154&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>My <a title="StrongSwan on OpenWRT" href="http://robwicks.wordpress.com/2011/04/05/strongswan-on-openwrt/">issues with Strongswan in the OpenWRT trunk</a> are now resolved. Strongswan 4.5.1-1 is available.</p>
<br />Filed under: <a href='http://robwicks.wordpress.com/category/encryption/'>encryption</a>, <a href='http://robwicks.wordpress.com/category/linux/'>linux</a>, <a href='http://robwicks.wordpress.com/category/linux/openwrt/'>OpenWRT</a> Tagged: <a href='http://robwicks.wordpress.com/tag/linux/'>linux</a>, <a href='http://robwicks.wordpress.com/tag/openwrt-2/'>OpenWrt</a>, <a href='http://robwicks.wordpress.com/tag/router/'>Router</a>, <a href='http://robwicks.wordpress.com/tag/strongswan/'>Strongswan</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/robwicks.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/robwicks.wordpress.com/154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/robwicks.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/robwicks.wordpress.com/154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/robwicks.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/robwicks.wordpress.com/154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/robwicks.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/robwicks.wordpress.com/154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/robwicks.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/robwicks.wordpress.com/154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/robwicks.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/robwicks.wordpress.com/154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/robwicks.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/robwicks.wordpress.com/154/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=154&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" /><img src="http://feeds.feedburner.com/~r/RobWickssRandomRamblings/~4/a44MAuFYlYI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://robwicks.wordpress.com/2011/05/23/strongswan-4-5-1-now-in-the-openwrt-trunk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bbe1b95054377e4b32b421c957748a2c?s=96&amp;d=identicon&amp;r=G" medium="image">
			<media:title type="html">robwicks</media:title>
		</media:content>
	<feedburner:origLink>http://robwicks.wordpress.com/2011/05/23/strongswan-4-5-1-now-in-the-openwrt-trunk/</feedburner:origLink></item>
		<item>
		<title>StrongSwan on OpenWRT</title>
		<link>http://feedproxy.google.com/~r/RobWickssRandomRamblings/~3/ZtsZTDhCYTs/</link>
		<comments>http://robwicks.wordpress.com/2011/04/05/strongswan-on-openwrt/#comments</comments>
		<pubDate>Tue, 05 Apr 2011 13:45:58 +0000</pubDate>
		<dc:creator>Robert Wicks</dc:creator>
				<category><![CDATA[linux]]></category>
		<category><![CDATA[OpenWRT]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[DD-WRT]]></category>
		<category><![CDATA[IPSec]]></category>
		<category><![CDATA[Linksys WRT54G series]]></category>
		<category><![CDATA[OpenWrt]]></category>
		<category><![CDATA[Router]]></category>
		<category><![CDATA[Strongswan]]></category>

		<guid isPermaLink="false">http://robwicks.wordpress.com/?p=151</guid>
		<description><![CDATA[I recently purchased a Buffalo WZR-HP-G300NH router and installed OpenWRT on it. I used the trunk version, but found that StrongSwan4 did not allow me to pass traffic, despite an identical configuration to my working Trendnet router. I can successfully connect, but my log files show an error &#8220;unable to add SAD entry.&#8221; My client [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=151&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I recently purchased a Buffalo WZR-HP-G300NH <a class="zem_slink" title="Router" rel="wikipedia" href="http://en.wikipedia.org/wiki/Router">router</a> and installed <a class="zem_slink" title="OpenWrt" rel="homepage" href="http://openwrt.org/">OpenWRT</a> on it. I used the trunk version, but found that StrongSwan4 did not allow me to pass traffic, despite an identical configuration to my <a title="Setting up a VPN Gateway on the Cheap" href="http://robwicks.wordpress.com/2011/02/22/setting-up-a-vpn-gateway-on-the-cheap/">working Trendnet router</a>. I can successfully connect, but my <a class="zem_slink" title="Data logger" rel="wikipedia" href="http://en.wikipedia.org/wiki/Data_logger">log files</a> show an error &#8220;unable to add SAD entry.&#8221; My client indicated no proposal. Though I have not discovered the full nature of the issue, I did notice that the <a href="http://downloads.openwrt.org/snapshots/trunk/">current OpenWRT trunk</a> does not include the kmod-mod-imq module. Since the networking component has changed, I wondered if that might be related. When I installed the <a href="http://downloads.openwrt.org/backfire/10.03.1-rc4/">10.03.1-rc4 version of OpenWRT</a> instead, things worked again.</p>
<br />Filed under: <a href='http://robwicks.wordpress.com/category/linux/'>linux</a>, <a href='http://robwicks.wordpress.com/category/linux/openwrt/'>OpenWRT</a>, <a href='http://robwicks.wordpress.com/category/security/'>security</a> Tagged: <a href='http://robwicks.wordpress.com/tag/dd-wrt/'>DD-WRT</a>, <a href='http://robwicks.wordpress.com/tag/ipsec/'>IPSec</a>, <a href='http://robwicks.wordpress.com/tag/linksys-wrt54g-series/'>Linksys WRT54G series</a>, <a href='http://robwicks.wordpress.com/tag/openwrt-2/'>OpenWrt</a>, <a href='http://robwicks.wordpress.com/tag/router/'>Router</a>, <a href='http://robwicks.wordpress.com/tag/strongswan/'>Strongswan</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/robwicks.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/robwicks.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/robwicks.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/robwicks.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/robwicks.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/robwicks.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/robwicks.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/robwicks.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/robwicks.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/robwicks.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/robwicks.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/robwicks.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/robwicks.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/robwicks.wordpress.com/151/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=151&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" /><img src="http://feeds.feedburner.com/~r/RobWickssRandomRamblings/~4/ZtsZTDhCYTs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://robwicks.wordpress.com/2011/04/05/strongswan-on-openwrt/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bbe1b95054377e4b32b421c957748a2c?s=96&amp;d=identicon&amp;r=G" medium="image">
			<media:title type="html">robwicks</media:title>
		</media:content>
	<feedburner:origLink>http://robwicks.wordpress.com/2011/04/05/strongswan-on-openwrt/</feedburner:origLink></item>
		<item>
		<title>Setting up a VPN Gateway on the Cheap</title>
		<link>http://feedproxy.google.com/~r/RobWickssRandomRamblings/~3/cw4ehSiQ_uA/</link>
		<comments>http://robwicks.wordpress.com/2011/02/22/setting-up-a-vpn-gateway-on-the-cheap/#comments</comments>
		<pubDate>Tue, 22 Feb 2011 19:50:28 +0000</pubDate>
		<dc:creator>Robert Wicks</dc:creator>
				<category><![CDATA[computing]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[OpenWRT]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Atheros]]></category>
		<category><![CDATA[Broadcom]]></category>
		<category><![CDATA[IKEv2]]></category>
		<category><![CDATA[IP address]]></category>
		<category><![CDATA[IPSec]]></category>
		<category><![CDATA[OpenVPN]]></category>
		<category><![CDATA[OpenWrt]]></category>
		<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strongswan]]></category>
		<category><![CDATA[Virtual private network]]></category>

		<guid isPermaLink="false">http://robwicks.wordpress.com/?p=112</guid>
		<description><![CDATA[OpenVPN Setup IPSec Setup Final Notes and Tips I recently got a hand-me-down Trendnet TEW-652BRP router. The label on it indicates that it is version 1.1R. Doing a bit of research, it seems as if the one I have is actually identical to the TEW-632BRP, so I compiled OpenWRT for the TEW-632BRP, and it worked [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=112&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="toclist">
<ul>
<li><a title="openvpn setup" href="#openvpn">OpenVPN Setup</a></li>
<li><a title="ipsec setup" href="#ipsec">IPSec Setup</a></li>
<li><a title="final" href="#final">Final Notes and Tips</a></li>
</ul>
</div>
<p>I recently got a hand-me-down Trendnet TEW-652BRP <a class="zem_slink" title="Router" href="http://en.wikipedia.org/wiki/Router" rel="wikipedia">router</a>. The label on it indicates that it is version 1.1R. Doing a bit of research, it seems as if the one I have is actually identical to the TEW-632BRP, so I compiled <a class="zem_slink" title="OpenWrt" href="http://openwrt.org/" rel="homepage">OpenWRT</a> for the TEW-632BRP, and it worked like a charm.&nbsp;The router uses an <a class="zem_slink" title="Atheros Communications" href="http://www.atheros.com" rel="homepage">Atheros</a> AR9130 rev2 <a class="zem_slink" title="Chipset" href="http://en.wikipedia.org/wiki/Chipset" rel="wikipedia">chipset</a> with a <a class="zem_slink" title="MIPS architecture" href="http://en.wikipedia.org/wiki/MIPS_architecture" rel="wikipedia">MIPS processor</a> running at 400Mhz. It features wireless N in the 2.4GHz range, 4MB of flash, which is fairly typical, and 32MB of <a class="zem_slink" title="Random-access memory" href="http://en.wikipedia.org/wiki/Random-access_memory" rel="wikipedia">RAM</a>, which is more than several I&#8217;ve seen. The processor is what intrigued me. It is well known that alternative, <a class="zem_slink" title="Linux" href="http://www.kernel.org/" rel="homepage">Linux-based</a> firmwares exist for consumer routers, <a href="http://lifehacker.com/178132/hack-attack-turn-your-60-router-into-a-600-router" target="_blank">which can offer an array of new features</a>. I have several compatible models myself. But most of the older <a class="zem_slink" title="Broadcom" href="http://www.broadcom.com/" rel="homepage">Broadcom</a> chipset models have fairly slow processors, so some applications, such as <a class="zem_slink" title="Virtual private network" href="http://en.wikipedia.org/wiki/Virtual_private_network" rel="wikipedia">VPNs</a>, perform only moderately well on them.</p>
<p>One of my favorite VPN products is <a class="zem_slink" title="OpenVPN" href="http://openvpn.net/index.php/open-source.html" rel="homepage">OpenVPN</a>. It performs well, and is simple to set up. A couple of years ago, <a href="http://www1.cse.wustl.edu/~jain/cse567-08/ftp/ovpn/index.html" target="_blank">an excellent analysis of the performance of OpenVPN on a consumer grade router was published</a>. For most home connections, you will get plenty of throughput using either of the VPN solutions we will be setting up. In order to get this up and running, first you must flash the router to get rid of the firmware which came with it and replace it with something altogether more powerful: <a title="OpenWrt: Wireless Freedom" href="http://www.openwrt.org" target="_blank">OpenWrt</a>. Download the <a href="http://downloads.openwrt.org/snapshots/trunk/ar71xx/OpenWrt-ImageBuilder-ar71xx-for-Linux-x86_64.tar.bz2">backfire image builder from the trunk</a>. Support for this chipset is newer than the Broadcom chipsets in the original Linksys <a class="zem_slink" title="Linksys WRT54G series" href="http://en.wikipedia.org/wiki/Linksys_WRT54G_series" rel="wikipedia">WRT-54G</a>(L) and OpenWrt is under constant development, and the trunk build has run much better than the others on my router. The features I want really push the limits of the storage, so I had to just drop wifi support. Fortunately, I have other wireless routers which I can use for access points on my home network. So these directions are for a command-line-only, wired-access-only router and VPN endpoint. After you get the builder, run</p>
<p>&#8220;tar -jxvf&nbsp;OpenWrt-ImageBuilder-ar71xx-for-Linux-x86_64.tar.bz2;cd&nbsp;OpenWrt-ImageBuilder-ar71xx-for-Linux-x86_64&#8243;</p>
<p>After you get into the directory, run something like the make command below.</p>
<blockquote><p>make image PROFILE=&#8221;TEW632BRP&#8221; PACKAGES=&#8221;base-files busybox ddns-scripts dnsmasq dropbear firewall hotplug2 ip iptables iptables-mod-conntrack iptables-mod-conntrack-extra iptables-mod-filter iptables-mod-imq iptables-mod-ipopt iptables-mod-ipsec iptables-mod-nat iptables-mod-nat-extra kernel kmod-button-hotplug kmod-crypto-aes kmod-crypto-authenc kmod-crypto-core kmod-crypto-des kmod-crypto-hmac kmod-crypto-md5 kmod-crypto-sha1 kmod-input-core kmod-input-gpio-buttons kmod-input-polldev kmod-ipsec kmod-ipsec4 kmod-ipt-conntrack kmod-ipt-conntrack-extra kmod-ipt-core kmod-ipt-filter kmod-ipt-imq kmod-ipt-ipopt kmod-ipt-ipsec kmod-ipt-nat kmod-ipt-nat-extra kmod-ipt-nathelper kmod-iptunnel4 kmod-leds-gpio kmod-sched kmod-textsearch kmod-tun libc libgcc <a class="zem_slink" title="GNU Multi-Precision Library" href="http://gmplib.org/" rel="homepage">libgmp</a> libiptc liblzo libnl-tiny libopenssl libpthread librt libuci libxtables mini-snmpd miniupnpd mtd openvpn opkg qos-scripts strongswan4 strongswan4-app-charon strongswan4-app-pluto strongswan4-mod-aes strongswan4-mod-attr strongswan4-mod-des strongswan4-mod-dnskey strongswan4-mod-fips-prf strongswan4-mod-gmp strongswan4-mod-hmac strongswan4-mod-kernel-netlink strongswan4-mod-md5 strongswan4-mod-pem strongswan4-mod-pgp strongswan4-mod-pkcs1 strongswan4-mod-pubkey strongswan4-mod-random strongswan4-mod-resolve strongswan4-mod-sha1 strongswan4-mod-sha2 strongswan4-mod-stroke strongswan4-mod-updown strongswan4-mod-x509 strongswan4-mod-xcbc strongswan4-utils tc uci udevtrigger -vsc7385-ucode-ap83 -vsc7385-ucode-pb44 -vsc7395-ucode-ap83 -vsc7395-ucode-pb44 zlib -kmod-ath9k -wpad-mini&#8221;</p></blockquote>
<p>This will install Strongswan and OpenVPN, but, due to only have 4MB of flash storage to work with, will not install the web interface, so we will be doing everything from the command line. After the command above gives you your image, you will need to choose the appropriate one to flash your router. If you are going from the factory firmware, you need to use the recovery image, which, when I build it, is called &#8220;openwrt-ar71xx-generic-tew-632brp-recovery-squashfs-factory.bin.&#8221;</p>
<p>You can then flash your firmware by unplugging it, holding down the reset button, plugging it in while the reset button is held down for about 10 seconds, then setting your computer&#8217;s <a class="zem_slink" title="IP address" href="http://en.wikipedia.org/wiki/IP_address" rel="wikipedia">IP address</a> to 192.168.0.2 and browsing to 192.168.0.1. Upload the file and flash away. The router will eventually reboot and have an IP address of 192.168.1.1.</p>
<p>You can then set your computer&#8217;s IP address to 192.168.1.2 and telnet into 192.168.1.1. The router will allow you in with no password. You can issue the &#8220;passwd&#8221; command to set the root password, which I recommend. Once you do this, however, you will have to use SSH to log into the router, as telnet is disabled when the root password is set.</p>
<h3 id="openvpn">OpenVPN Setup</h3>
<p>OpenVPN is a very easy to configure, cross-platform, open source VPN, and it now has wide support on third party firmwares such as <a title="OpenWRT Firmware Homepage" href="http://openwrt.org" target="_blank">OpenWRT</a>, <a title="DD-WRT Homepage" href="http://www.dd-wrt.com/" target="_blank">DD-WRT</a>, and <a title="Tomato Firmware Homepage" href="http://www.polarcloud.com/tomato" target="_blank">Tomato</a> (but you will need either <a title="Tomato VPN Firmware Homepage" href="http://tomatovpn.keithmoyer.com/" target="_blank">TomatoVPN</a> or <a title="Tomato USB Firmware Homepage" href="http://tomatousb.org/" target="_blank">TomatoUSB</a>). IPSec has the advantage of being a standard which can interoperate with a variety of devices and operating systems where OpenVPN is not available. I figure why not do both? We are going to use certificates to authenticate both of them, so with a bit of care, we can use the exact same certifcates and keys on our router for both services, saving us a little bit of storage. I did my certificate generation on Ubuntu 10.10, but you could use anything which runs OpenVPN and <a title="OpenSSL Homepage" href="http://www.openssl.org" target="_blank">OpenSSL</a>. On Ubuntu, run</p>
<blockquote><p>sudo apt-get install openvpn</p></blockquote>
<p>After the installation completes, copy the entire&nbsp;/usr/share/doc/openvpn/examples/easy-rsa/2.0 directory into your home directory with</p>
<blockquote><p>cp -r&nbsp;/usr/share/doc/openvpn/examples/easy-rsa/2.0 $HOME/</p></blockquote>
<p>This will give you a &#8220;2.0&#8243; directory in your home directory. Cd into that directory, and edit the vars file so that it has your organization and personalized information (this is optional). Then edit the openssl.cnf file. You will modify it so that the certificates it generates will be suitable for both OpenVPN and Windows 7&#8242;s implementation of IPSec. Go to line 196 in the file, the extendedKeyUsage line. You will also add a new line after this one. Together, they read:</p>
<blockquote><p>extendedKeyUsage=clientAuth, serverAuth, 1.3.6.1.5.5.8.2.2<br />
subjectAltName=DNS:Your.Internet.DNS.Hostname</p></blockquote>
<p>In place of Your.Internet.DNS.Hostname, put your computer&#8217;s hostname. If you are on a home Internet connection, you should use one of the dynamic DNS providers such as DynDNS.com. These lines will enable the Windows 7 IKEv2 VPN client to work with StrongSwan. Be sure to follow the directions <a href="http://wiki.strongswan.org/projects/strongswan/wiki/Windows7">here</a>. You can then run the following commands.</p>
<blockquote><p>. ./vars<br />
mkdir keys<br />
./clean-all<br />
./build-dh<br />
./build-ca<br />
./build-key-server Your.Internet.DNS.Hostname<br />
./build-key-pkcs12 client1</p></blockquote>
<p>As before, replace the Your.Internet.DNS.Hostname with your Internet hostname. One of the good things about the build-key-pkcs12 script is that it generates everything you will need for OpenVPN clients on both Windows and Linux. You will find client1.key, client1.csr, client1.crt, and client1.p12 under the keys directory after running the last command. You will also see files with the same extensions (except the p12 file) prefixed by your Internet hostname. Those files will be installed on your OpenWRT VPN endpoint. The client1 files will be installed on your laptop (or whatever will be connecting into your VPN endpoint). First, we need to copy the server keys we generated into the appropriate places. We will use the default paths for StrongSwan, but OpenVPN will also use them. Run:</p>
<blockquote><p>scp keys/Your.Internet.DNS.Hostname.crt root@:/etc/ipsec.d/certs/Your.Internet.DNS.Hostname.crt</p>
<p>scp keys/Your.Internet.DNS.Hostname.key root@:/etc/ipsec.d/certs/Your.Internet.DNS.Hostname.key</p>
<p>scp keys/ca.crt root@:/etc/ipsec.d/cacerts/ca.crt</p>
<p>scp keys/dh1024.pem root@:/etc/openvpn/</p></blockquote>
<p>SSH into your OpenWRT router and run:</p>
<blockquote><p>vi /etc/openvpn/my-vpn.conf</p></blockquote>
<p>This will create the configuration file you will use, which you will fill with something like this:</p>
<blockquote><p>daemon<br />
server 10.10.10.0 255.255.255.0<br />
proto udp<br />
port 1194<br />
dev tun0<br />
comp-lzo adaptive<br />
keepalive 15 60<br />
verb 2<br />
push &#8220;route 192.168.0.0 255.255.255.0&#8243;<br />
ca /etc/ipsec.d/cacerts/ca.crt<br />
dh /etc/openvpn/dh1024.pem<br />
cert /etc/ipsec.d/certs/Your.Internet.DNS.Hostname.crt<br />
key /etc/ipsec.d/private/Your.Internet.DNS.Hostname.key<br />
tls-auth /etc/openvpn/ta.key 0</p></blockquote>
<p>You should customize the route to reflect the IP scheme of your internal network. You can also alter the server line to any arbitrary private network. Finally, you can change your port to something other than 1194. Notice that the last line refers to a file, ta.key, which we have not yet created. We can do that on the router itself with the command:</p>
<blockquote><p>openvpn &#8211;genkey &#8211;secret /etc/openvpn/ta.key</p></blockquote>
<p>Adding this to your OpenVPN configuration will defend against port scanning and DOS attacks. You will need to copy this file to your laptop as well. Your laptop&#8217;s OpenVPN configuration will contain something like this:</p>
<blockquote><p>client<br />
dev tun<br />
proto udp<br />
remote Your.Internet.DNS.Hostname 1194<br />
resolv-retry infinite<br />
nobind<br />
persist-key<br />
persist-tun<br />
ca /etc/ipsec.d/cacerts/ca.crt<br />
dh /etc/openvpn/dh1024.pem<br />
cert /etc/ipsec.d/certs/Your.Internet.DNS.Hostname.crt<br />
key /etc/ipsec.d/private/Your.Internet.DNS.Hostname.key<br />
tls-auth ta.key 1<br />
comp-lzo<br />
verb 3</p></blockquote>
<p>You now have a working OpenVPN configuration, but you still need to modify your firewall rules to allow traffic through. Run</p>
<blockquote><p>vi /etc/config/firewall</p></blockquote>
<p>Add the following lines to the end:</p>
<blockquote><p>config &#8216;rule&#8217;</p>
<blockquote><p>option &#8216;src&#8217; &#8216;wan&#8217;<br />
option &#8216;target&#8217; &#8216;ACCEPT&#8217;<br />
option &#8216;proto&#8217; &#8216;udp&#8217;<br />
option &#8216;dest_port&#8217; &#8217;1194&#8242;</p></blockquote>
</blockquote>
<p>Save the file. This will configure your firewall to accept inbound OpenVPN traffic. In order to pass the tunneled packets through, we edit the firewall.user file:</p>
<blockquote><p>vi /etc/firewall.user</p></blockquote>
<p>Add the following lines to that file:</p>
<blockquote><p>/usr/sbin/iptables -I INPUT -i tun+ -j ACCEPT<br />
/usr/sbin/iptables -I FORWARD -i tun+ -j ACCEPT</p></blockquote>
<p>This will allow your VPN to work. Just reboot the router and OpenVPN should work. Now, let&#8217;s get to IPSec.</p>
<h3 id="ipsec">IPSec Setup</h3>
<p>IPSec is actually more difficult to configure than OpenVPN, but, being a cross-platform standard, and enjoying kernel-level support, is still a nice feature to have on an Internet gateway. The crypto files have already been put in place, so we just need to edit the configuration. Run:</p>
<blockquote><p>vi /etc/ipsec.conf</p></blockquote>
<p>Modify the files so that it contains:</p>
<blockquote><p>config setup</p>
<blockquote><p>strictcrlpolicy=no<br />
nat_traversal=yes<br />
charondebug=all</p></blockquote>
<p>conn %default</p>
<blockquote><p>ikelifetime=60m<br />
keylife=20m<br />
rekeymargin=3m<br />
keyingtries=1</p></blockquote>
<p>conn nat-t</p>
<blockquote><p>authby=rsasig<br />
leftfirewall=yes<br />
left=%defaultroute<br />
leftcert=Your.Internet.DNS.Hostname.crt<br />
rightsourceip=10.8.8.0/24<br />
leftsubnet=192.168.0.0/24<br />
right=%any<br />
auto=add</p></blockquote>
</blockquote>
<p>Edit your /etc/ipsec.secrets file and fill it with:</p>
<blockquote><p>: RSA Your.Internet.DNS.Hostname.key</p></blockquote>
<p>Now, we allow the appropriate connections to the firewall. Edit the /etc/config/firewall file and add:</p>
<blockquote><p>config &#8216;rule&#8217;</p>
<blockquote><p>option &#8216;src&#8217; &#8216;wan&#8217;<br />
option &#8216;proto&#8217; &#8216;esp&#8217;<br />
option &#8216;target&#8217; &#8216;ACCEPT&#8217;</p></blockquote>
<p>config &#8216;rule&#8217;</p>
<blockquote><p>option &#8216;src&#8217; &#8216;wan&#8217;<br />
option &#8216;proto&#8217; &#8216;udp&#8217;<br />
option &#8216;dest_port&#8217; &#8217;500&#8242;<br />
option &#8216;target&#8217; &#8216;ACCEPT&#8217;</p></blockquote>
<p>config &#8216;rule&#8217;</p>
<blockquote><p>option &#8216;src&#8217; &#8216;wan&#8217;<br />
option &#8216;proto&#8217; &#8216;udp&#8217;<br />
option &#8216;dest_port&#8217; &#8217;4500&#8242;<br />
option &#8216;target&#8217; &#8216;ACCEPT&#8217;</p></blockquote>
<p>config &#8216;rule&#8217;</p>
<blockquote><p>option &#8216;src&#8217; &#8216;wan&#8217;<br />
option &#8216;proto&#8217; &#8216;ah&#8217;<br />
option &#8216;target&#8217; &#8216;ACCEPT&#8217;</p></blockquote>
</blockquote>
<p>Finally, add the following to /etc/firewall.user to enable all the traffic to pass, even to the OpenWRT router itself:</p>
<blockquote><p>/usr/sbin/iptables -I INPUT&nbsp; -m policy &#8211;dir in &#8211;pol ipsec &#8211;proto esp -j ACCEPT<br />
/usr/sbin/iptables -I FORWARD&nbsp; -m policy &#8211;dir in &#8211;pol ipsec &#8211;proto esp -j ACCEPT<br />
/usr/sbin/iptables -I FORWARD&nbsp; -m policy &#8211;dir out &#8211;pol ipsec &#8211;proto esp -j ACCEPT<br />
/usr/sbin/iptables -I OUTPUT&nbsp;&nbsp; -m policy &#8211;dir out &#8211;pol ipsec &#8211;proto esp -j ACCEPT</p>
<p>This gives full access to all the tunneled traffic. On a Windows 7 client, you can follow <a title="StrongSwan Windows 7 Configuration" href="http://wiki.strongswan.org/projects/strongswan/wiki/Windows7" target="_blank">this guide</a>. Note that you will have to manually add the route for your home network on Windows 7, due to the limitations of the Agile VPN client. I run a command prompt as administrator and run</p>
<p>route add 192.168.0.0 mask 255.255.255.0 10.8.8.1</p></blockquote>
<p>after I connect. Traffic then passes. Things are much easier if you are using StrongSwan as the client. Just edit the /etc/ipsec.conf file on your Linux laptop client to contain the following:</p>
<blockquote><p>config setup</p>
<blockquote><p>charondebug=all<br />
nat_traversal=yes<br />
charonstart=yes<br />
plutostart=yes</p></blockquote>
<p>conn roadwarrior</p>
<blockquote><p>left=%defaultroute<br />
leftcert=client1.crt<br />
leftfirewall=yes<br />
leftauth=rsasig<br />
leftsourceip=%modeconfig<br />
right=Your.Internet.DNS.Hostname<br />
rightcert=Your.Internet.DNS.Hostname.crt<br />
keyexchange=ikev2<br />
rightsubnet=192.168.0.0/24<br />
auto=add</p></blockquote>
</blockquote>
<p>As you can see, you will be copying your router cert (and only the cert, not the private key) to your client. You will also copy your client1 key and cert. In a similar manner to the router, your /etc/ipsec.secrets file will contain</p>
<blockquote><p>: RSA client1.key</p></blockquote>
<p>You can read more on the Strongswan client configuration <a href="http://www.strongswan.org/docs/readme4.htm#section_2.6">here</a>. Once you have Strongswan configured, you can start ipsec, then issue</p>
<blockquote><p>ipsec up roadwarrior</p></blockquote>
<p>to start the tunnel.</p>
<h3 id="final">Final Notes and Tips</h3>
<p>You can actually replace the rightcert line with &#8220;rightid=%any&#8221; which is a better practice, from what I gather from the StrongSwan mailing list. That is how I have modified my own setup. Also, <strong>note that the Ubuntu package is actually broken</strong>, because it does not use socket-raw. To fix this, remove /usr/lib/ipsec/plugins/libstrongswan-socket-d*&nbsp;and restart the daemon. Or, you can do what I did and build the latest StrongSwan from source.</p>
<p>Be sure to look at the various documentation pages for OpenWRT, OpenVPN, and Strongswan. They have a lot of very useful information. One of the nice things you can do when you have your VPN setup working fully is completely disable all other remote access to your network. You can make your router invisible on the Internet, yet still allow full access to your home resources. With more powerful routers, especially ones with more storage, you can add useful packages to allow full SNMP support, traffic monitoring, the GUI interface, or port knocking.</p>
<p>If you have any questions, please post them in the comments or email me.</p>
<br />Filed under: <a href='http://robwicks.wordpress.com/category/computing/'>computing</a>, <a href='http://robwicks.wordpress.com/category/linux/'>linux</a>, <a href='http://robwicks.wordpress.com/category/linux/openwrt/'>OpenWRT</a>, <a href='http://robwicks.wordpress.com/category/security/'>security</a> Tagged: <a href='http://robwicks.wordpress.com/tag/atheros/'>Atheros</a>, <a href='http://robwicks.wordpress.com/tag/broadcom/'>Broadcom</a>, <a href='http://robwicks.wordpress.com/tag/ikev2/'>IKEv2</a>, <a href='http://robwicks.wordpress.com/tag/ip-address/'>IP address</a>, <a href='http://robwicks.wordpress.com/tag/ipsec/'>IPSec</a>, <a href='http://robwicks.wordpress.com/tag/linux/'>linux</a>, <a href='http://robwicks.wordpress.com/tag/openvpn/'>OpenVPN</a>, <a href='http://robwicks.wordpress.com/tag/openwrt-2/'>OpenWrt</a>, <a href='http://robwicks.wordpress.com/tag/operating-systems/'>Operating Systems</a>, <a href='http://robwicks.wordpress.com/tag/security-2/'>Security</a>, <a href='http://robwicks.wordpress.com/tag/strongswan/'>Strongswan</a>, <a href='http://robwicks.wordpress.com/tag/virtual-private-network/'>Virtual private network</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/robwicks.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/robwicks.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/robwicks.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/robwicks.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/robwicks.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/robwicks.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/robwicks.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/robwicks.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/robwicks.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/robwicks.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/robwicks.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/robwicks.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/robwicks.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/robwicks.wordpress.com/112/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=112&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" /><img src="http://feeds.feedburner.com/~r/RobWickssRandomRamblings/~4/cw4ehSiQ_uA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://robwicks.wordpress.com/2011/02/22/setting-up-a-vpn-gateway-on-the-cheap/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bbe1b95054377e4b32b421c957748a2c?s=96&amp;d=identicon&amp;r=G" medium="image">
			<media:title type="html">robwicks</media:title>
		</media:content>
	<feedburner:origLink>http://robwicks.wordpress.com/2011/02/22/setting-up-a-vpn-gateway-on-the-cheap/</feedburner:origLink></item>
		<item>
		<title>Noscript And Zimbra Problem</title>
		<link>http://feedproxy.google.com/~r/RobWickssRandomRamblings/~3/VkQguEmXfCo/</link>
		<comments>http://robwicks.wordpress.com/2010/11/06/noscript-and-zimbra-problem/#comments</comments>
		<pubDate>Sat, 06 Nov 2010 13:23:39 +0000</pubDate>
		<dc:creator>Robert Wicks</dc:creator>
				<category><![CDATA[computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ABE]]></category>
		<category><![CDATA[Application Boundaries Enforce]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Noscript]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Zimbra]]></category>

		<guid isPermaLink="false">https://robwicks.wordpress.com/2010/11/06/noscript-and-zimbra-problem/</guid>
		<description><![CDATA[I log into a Zimbra server for email. I may be logged in on the local network, from outside, over the Internet, or across a VPN. The hostname is always the same. I found that I would have to actually quit Firefox in order to log back into Zimbra if I initiated a session over [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=109&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I log into a Zimbra server for email. I may be logged in on the local network, from outside, over the Internet, or across a VPN. The hostname is always the same. I found that I would have to actually quit Firefox in order to log back into Zimbra if I initiated a session over the Internet, and later made a VPN connection. I would see a white screen with a link in the upper left corner which said [Sign Out]. Clicking it did nothing. I actually had to restart Firefox. I discovered that this happened because of Noscript&#8217;s ABE protection. I did not wish to disable this, as it is a useful security feature. The solution is to go into the NoScript options, under ABE, and edit the SYSTEM settings. It normally says</p>
<blockquote><p># Prevent Internet sites from requesting LAN resources.<br />
Site LOCAL<br />
Accept from LOCAL<br />
Deny</p></blockquote>
<p>I added this line after the Accept lin:</p>
<blockquote><p>Accept ALL from *.&lt;mydomainname&gt;</p></blockquote>
<p>That fixed the issue. It might be advisable for people who use Noscript in a corporate environment with VPN access to add this to their ABE settings in order to prevent web application failures.</p>
<br />Filed under: <a href='http://robwicks.wordpress.com/category/computing/'>computing</a>, <a href='http://robwicks.wordpress.com/category/security/'>security</a> Tagged: <a href='http://robwicks.wordpress.com/tag/abe/'>ABE</a>, <a href='http://robwicks.wordpress.com/tag/application-boundaries-enforce/'>Application Boundaries Enforce</a>, <a href='http://robwicks.wordpress.com/tag/firefox/'>Firefox</a>, <a href='http://robwicks.wordpress.com/tag/noscript/'>Noscript</a>, <a href='http://robwicks.wordpress.com/tag/vpn/'>VPN</a>, <a href='http://robwicks.wordpress.com/tag/zimbra/'>Zimbra</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/robwicks.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/robwicks.wordpress.com/109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/robwicks.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/robwicks.wordpress.com/109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/robwicks.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/robwicks.wordpress.com/109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/robwicks.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/robwicks.wordpress.com/109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/robwicks.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/robwicks.wordpress.com/109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/robwicks.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/robwicks.wordpress.com/109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/robwicks.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/robwicks.wordpress.com/109/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=109&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" /><img src="http://feeds.feedburner.com/~r/RobWickssRandomRamblings/~4/VkQguEmXfCo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://robwicks.wordpress.com/2010/11/06/noscript-and-zimbra-problem/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bbe1b95054377e4b32b421c957748a2c?s=96&amp;d=identicon&amp;r=G" medium="image">
			<media:title type="html">robwicks</media:title>
		</media:content>
	<feedburner:origLink>http://robwicks.wordpress.com/2010/11/06/noscript-and-zimbra-problem/</feedburner:origLink></item>
		<item>
		<title>Sexuality, the State, and the Death of Black Manhood</title>
		<link>http://feedproxy.google.com/~r/RobWickssRandomRamblings/~3/ShUcWEEObIg/</link>
		<comments>http://robwicks.wordpress.com/2010/10/13/sexuality-the-state-and-the-death-of-black-manhood/#comments</comments>
		<pubDate>Thu, 14 Oct 2010 01:22:37 +0000</pubDate>
		<dc:creator>Robert Wicks</dc:creator>
				<category><![CDATA[blacks]]></category>
		<category><![CDATA[liberarianism]]></category>
		<category><![CDATA[political correctness]]></category>
		<category><![CDATA[race]]></category>
		<category><![CDATA[war on drugs]]></category>
		<category><![CDATA[welfare]]></category>

		<guid isPermaLink="false">https://robwicks.wordpress.com/?p=101</guid>
		<description><![CDATA[Recently, my college friends and myself were discussing a recent article in Vibe magazine on the experiences of a flamboyantly gay man at Morehouse College, and the response of the school’s president. I shared the two articles with family and friends, and the inevitable question “what has happened to black men?” came up. It seems [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=101&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Recently, my college friends and myself were discussing a recent article in Vibe magazine on the <a href="http://www.vibe.com/content/mean-girls-morehouse" target="_blank">experiences of a flamboyantly gay man at Morehouse College</a>, and the <a href="http://www.vibe.com/posts/morehouse-president-writes-letter-alumni-addressing-mean-girls" target="_blank">response of the school’s president</a>. I shared the two articles with family and friends, and the inevitable question “what has happened to black men?” came up. It seems clear to me that the main things which have happened are the reasons I despise Lyndon B. Johnson and Ronald Reagan. The war on poverty brought us welfare, which pushed a lot of black men from homes in the name of easy (or easier) money. That was Johnson. Reagan escalated the war on drugs, which further devastated the black family, especially the black males. Can anyone really claim that it is better for a black guy to be locked up for smoking or selling weed, rather than going to a community college and getting himself a job some day? Is controlling what someone does with his own body so very important? Is promoting the creation of drug gangs, then promoting the increase in the intrusiveness and violence of policing something we can really describe as &#8220;good?&#8221;</p>
<p>Because of these two factors, black men have fewer male role models. Many men emulate their mothers, unsurprising, as so many men are reared without fathers. Some of those mothers are educated, so that is fine as far as education goes. These men will pursue education. But they do not act like men. This is true even of many heterosexual men. Among any sufficiently large population, a number of gay people is to be expected. I do not find it surprising that a segment of the gay population would take emulating their mothers to an extreme that the straight men would not.</p>
<p>I predicted years ago that black higher education would become increasingly gay, and specifically, effeminately so. The war on drugs has devastated the ranks of black men in black communities to such an extent that female role models are, all too often, the best role models for success that black boys have. The testosterone has been depleted from the segments of black society most in need of it. This is one of the many tragedies brought to neighborhoods across the nation by the desire to force moral choices on others “for their own good.” And, while I targeted those two presidents for specific criticism, we can hardly &#8220;blame whitey&#8221; for this one. There are lots of people who are black drug warriors. Pretty much every black politician, including Obama, is a drug warrior. Eric Holder, his pick for Attorney General, <a href="http://www.washingtoncitypaper.com/blogs/citydesk/2008/11/19/eric-holder-extreme-drug-warrior/" target="_blank">is an especially fervent drug warrior</a>. As far as I am concerned, we should treat blacks who support the war on drugs the same as we would treat a black guy doing a minstrel show in full blackface at an NAACP meeting. They deserve nothing but derision for being essentially black slave overseers. They profit from promoting oppression.</p>
<p>(Crossposted at <a href="http://www.libertarianstandard.com/2010/10/13/sexuality-the-state-and-the-death-of-black-manhood/" target="_blank">The Libertarian Standard</a>)</p>
<br />Filed under: <a href='http://robwicks.wordpress.com/category/blacks/'>blacks</a>, <a href='http://robwicks.wordpress.com/category/liberarianism/'>liberarianism</a>, <a href='http://robwicks.wordpress.com/category/political-correctness/'>political correctness</a>, <a href='http://robwicks.wordpress.com/category/race/'>race</a>, <a href='http://robwicks.wordpress.com/category/war-on-drugs/'>war on drugs</a>, <a href='http://robwicks.wordpress.com/category/welfare/'>welfare</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/robwicks.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/robwicks.wordpress.com/101/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/robwicks.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/robwicks.wordpress.com/101/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/robwicks.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/robwicks.wordpress.com/101/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/robwicks.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/robwicks.wordpress.com/101/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/robwicks.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/robwicks.wordpress.com/101/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/robwicks.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/robwicks.wordpress.com/101/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/robwicks.wordpress.com/101/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/robwicks.wordpress.com/101/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=101&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" /><img src="http://feeds.feedburner.com/~r/RobWickssRandomRamblings/~4/ShUcWEEObIg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://robwicks.wordpress.com/2010/10/13/sexuality-the-state-and-the-death-of-black-manhood/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bbe1b95054377e4b32b421c957748a2c?s=96&amp;d=identicon&amp;r=G" medium="image">
			<media:title type="html">robwicks</media:title>
		</media:content>
	<feedburner:origLink>http://robwicks.wordpress.com/2010/10/13/sexuality-the-state-and-the-death-of-black-manhood/</feedburner:origLink></item>
		<item>
		<title>Twitter’s Pro-Freedom Terms of Service</title>
		<link>http://feedproxy.google.com/~r/RobWickssRandomRamblings/~3/U8eXTOrHvn8/</link>
		<comments>http://robwicks.wordpress.com/2010/10/12/twitters-pro-freedom-terms-of-service/#comments</comments>
		<pubDate>Tue, 12 Oct 2010 22:37:15 +0000</pubDate>
		<dc:creator>Robert Wicks</dc:creator>
				<category><![CDATA[Intellectual Property]]></category>

		<guid isPermaLink="false">http://robwicks.wordpress.com/?p=93</guid>
		<description><![CDATA[Over at the online photography magazine, Photofocus, Scott Bourne warns photographers of the terms of service they may unwittingly agree to by posting a picture on Twitter. From the article: Ask a real lawyer (not some guy named Larry who plays one on your local camera club forum) what this means. I did. My lawyer [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=93&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Over at the online photography magazine, <a href="http://photofocus.com" target="_blank">Photofocus</a>, Scott Bourne <a href="http://photofocus.com/2010/10/12/photos-on-twitter-what-you-should-know/" target="_blank">warns photographers</a> of the terms of service they may unwittingly agree to by posting a picture on Twitter. From the article:</p>
<blockquote><p>Ask a real lawyer (not some guy named Larry who plays one on your  local camera club forum) what this means. I did. My lawyer says it means  that Twitter can do pretty much anything it wants with my photos (other  than claim actual Copyright to them) and there’s nothing I can do about  that. Is that an issue for you personally? Maybe not. It’s unlikely it  will impact you if you aren’t trying to sell your photos. But if you  are, read on.</p>
<p>As a professional photographer, I can’t sell “exclusive” rights to  any image I decide to publish on Twitter. The reason is that once it is  published on Twitter, there is no exclusivity left. That could be  expensive. As professionals, we need to decide whether the exposure we  get via Twitter is worth that trade off. For some of us the answer is  yes – for others the answer is no. The purpose of this post is to get  you to understand that you will have to make some hard choices. I am  hoping they are informed choices, no matter what you decide.</p></blockquote>
<p>In the case of the Twitter TOS, it seems that the terms Twitter stipulates are exactly the pro-freedom position: you can do whatever you want with the stuff you own (<em>stuff</em>, not <em>ideas</em>) unless you have contracted some other arrangement. Twitter owns the servers. You own the photo, sure, but you still have the photo after you uploaded it. What the uploader is actually doing is <strong><em>using Twitter&#8217;s stuff to create a copy on Twitter&#8217;s servers</em></strong>. For the photographer to then claim that he has the right to determine what Twitter does with it is like going to someone&#8217;s house and using a dollar bill left on a counter to make origami, then demanding the right to determine what happens to it as a result of your pattern rearrangement. It is nonsense from the start.</p>
<p>(<a href="http://www.libertarianstandard.com/2010/10/12/twitters-pro-freedom-terms-of-service/" target="_blank">crossposted </a>at <a title="TLS" href="http://www.libertarianstandard.com" target="_blank">The Libertarian Standard</a>)</p>
<br />Filed under: <a href='http://robwicks.wordpress.com/category/intellectual-property/'>Intellectual Property</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/robwicks.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/robwicks.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/robwicks.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/robwicks.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/robwicks.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/robwicks.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/robwicks.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/robwicks.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/robwicks.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/robwicks.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/robwicks.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/robwicks.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/robwicks.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/robwicks.wordpress.com/93/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=93&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" /><img src="http://feeds.feedburner.com/~r/RobWickssRandomRamblings/~4/U8eXTOrHvn8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://robwicks.wordpress.com/2010/10/12/twitters-pro-freedom-terms-of-service/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bbe1b95054377e4b32b421c957748a2c?s=96&amp;d=identicon&amp;r=G" medium="image">
			<media:title type="html">robwicks</media:title>
		</media:content>
	<feedburner:origLink>http://robwicks.wordpress.com/2010/10/12/twitters-pro-freedom-terms-of-service/</feedburner:origLink></item>
		<item>
		<title>Automounting Truecrypt in Linux</title>
		<link>http://feedproxy.google.com/~r/RobWickssRandomRamblings/~3/wUZ2AQzATPE/</link>
		<comments>http://robwicks.wordpress.com/2010/07/19/automounting-truecrypt-in-linux/#comments</comments>
		<pubDate>Mon, 19 Jul 2010 05:35:02 +0000</pubDate>
		<dc:creator>Robert Wicks</dc:creator>
				<category><![CDATA[computing]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[Truecrypt]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[truecrypt]]></category>

		<guid isPermaLink="false">http://robwicks.wordpress.com/?p=83</guid>
		<description><![CDATA[I have a dual boot system with Windows 7 and Ubuntu 10.04. In order to secure the system, I have system encryption with Truecrypt and encrypted LVM in Ubuntu. I need to access my Windows files from within Ubuntu. After a bit of searching around the Internet, I pieced together this command line, which I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=83&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I have a dual boot system with Windows 7 and Ubuntu 10.04. In order to secure the system, I have system encryption with <a title="Truecrypt" href="http://truecrypt.org" target="_blank">Truecrypt</a> and encrypted LVM in <a title="Ubuntu" href="http://ubuntu.com" target="_blank">Ubuntu</a>. I need to access my Windows files from within Ubuntu. After a bit of searching around the Internet, I pieced together this command line, which I put in /etc/rc.local. Since my system is fully encrypted and used by only me, I&#8217;m not concerned about the password being in /etc/rc.local. I installed the Truecrypt console version.</p>
<p>I added the following line to /etc/rc.local:</p>
<p>echo &#8220;MyTruecryptPassPhrase&#8221; | /usr/local/bin/truecrypt -t -m system -k &#8220;&#8221; -p &#8221;&#8221; &#8211;protect-hidden=no &#8211;fs-options=rw,noatime,umask=000 &#8211;filesystem=ntfs-3g /dev/&lt;windows partition&gt; /&lt;local mount point&gt;</p>
<p>By echoing the passphrase and piping it to the Truecrypt command, we avoid having it show up in the &#8216;ps -ef&#8217; command. The filesystem will be mounted with 0777 permissions.</p>
<p>I have found that it is even possible to mount outer partitions (with hidden partitions inside) using this method, and protecting the hidden partition. The command is as follows:</p>
<p>echo &#8220;HiddenPartitionPassphrase\n\nOuterPartitionPassphrase&#8221; | /usr/bin/truecrypt -t -k &#8220;&#8221; -p &#8220;&#8221;  &#8211;protect-hidden=yes &#8211;fs-options=rw,noatime,umask=000  /dev/sda2 /windows</p>
<p>By using the hidden OS feature in Truecrypt, it is possible to triple boot your computer, with all data on the drive except for the /boot partition in Linux being encrypted. Since no secret information is stored in /boot, this is not a problem.</p>
<br />Filed under: <a href='http://robwicks.wordpress.com/category/computing/'>computing</a>, <a href='http://robwicks.wordpress.com/category/encryption/'>encryption</a>, <a href='http://robwicks.wordpress.com/category/linux/'>linux</a>, <a href='http://robwicks.wordpress.com/category/truecrypt/'>Truecrypt</a>, <a href='http://robwicks.wordpress.com/category/ubuntu/'>ubuntu</a> Tagged: <a href='http://robwicks.wordpress.com/tag/encryption/'>encryption</a>, <a href='http://robwicks.wordpress.com/tag/linux/'>linux</a>, <a href='http://robwicks.wordpress.com/tag/truecrypt-2/'>truecrypt</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/robwicks.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/robwicks.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/robwicks.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/robwicks.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/robwicks.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/robwicks.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/robwicks.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/robwicks.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/robwicks.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/robwicks.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/robwicks.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/robwicks.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/robwicks.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/robwicks.wordpress.com/83/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=83&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" /><img src="http://feeds.feedburner.com/~r/RobWickssRandomRamblings/~4/wUZ2AQzATPE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://robwicks.wordpress.com/2010/07/19/automounting-truecrypt-in-linux/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bbe1b95054377e4b32b421c957748a2c?s=96&amp;d=identicon&amp;r=G" medium="image">
			<media:title type="html">robwicks</media:title>
		</media:content>
	<feedburner:origLink>http://robwicks.wordpress.com/2010/07/19/automounting-truecrypt-in-linux/</feedburner:origLink></item>
		<item>
		<title>Ubuntu thumb drive</title>
		<link>http://feedproxy.google.com/~r/RobWickssRandomRamblings/~3/SevilRP4pqE/</link>
		<comments>http://robwicks.wordpress.com/2010/04/22/ubuntu-thumb-driv/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 02:44:15 +0000</pubDate>
		<dc:creator>Robert Wicks</dc:creator>
				<category><![CDATA[linux]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[lucid]]></category>
		<category><![CDATA[thumb drive]]></category>
		<category><![CDATA[tmpfs]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://robwicks.wordpress.com/?p=71</guid>
		<description><![CDATA[Quick howto for moderately experienced Ubuntu users for installing Ubuntu on an easily updated flash drive.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=71&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I recently installed <a href="http://www.ubuntu.com/getubuntu/releasenotes/1004overview" target="_blank">Ubuntu 10.04 beta 2</a> (Lucid Lynx) on an Imation 4GB thumb drive. Ubuntu has a feature to install the live CD onto a thumb drive, but I have always found that solution a bit unsatisfying. I wanted an installation which could be updated and modified as I see fit. So, I wanted to use the thumb drive like a hard drive. Most of what I do allows me to forgo persistent local storage, but I did want that option, so I encrypted my home directory, which is an install option. One of the potential problems with that plan is the fact that flash storage, especially cheap flash storage, like the kind in a thumb drive, <a href="http://en.wikipedia.org/wiki/Flash_memory#Memory_wear" target="_blank">has a limited number of writes before it fails</a>.</p>
<p>installing Ubuntu onto a thumb drive, using it like a hard drive, is simple. Just run the normal install, clicking on the &#8220;Advanced&#8221; tab on the screen prior to the beginning of the actual install. The subsequent screen allows you to choose the location for the boot sector. Simply change the boot sector to the thumb device, and you are done there. For further details, go <a href="http://www.pendrivelinux.com/ubuntu-804-usb-hard-drive-install/">here</a>.</p>
<p>After the install, you can update your Ubuntu install as normal. Now, the next step is to do things which will extend the life of your thumb drive. Obviously, you do not want to have a swap file. I formatted the swap partition which Ubuntu automatically created and mounted that partition as /home. I also made use of tmpfs to mount some of the more heavily written areas in RAM, discarding them on each reboot. Here is what I did in /etc/fstab:</p>
<blockquote><p>tmpfs /var/tmp tmpfs noatime,rw,mode=1777 0 0<br />
tmpfs /tmp tmpfs noatime,rw,mode=1777 0 0<br />
tmpfs /var/cache/apt tmpfs noatime,rw 0 0<br />
tmpfs /var/log tmpfs noatime,rw 0 0</p></blockquote>
<p>Additionally, I added this to /etc/rc.local:</p>
<blockquote><p>mkdir -p /var/cache/apt/archives/partial<br />
mkdir /var/log/apt</p></blockquote>
<p>This means that the heavily written stuff, like logs, and the update cache for software, are written to RAM and discarded. The /etc/rc.local line is needed because apt-get requires both the archives and archives/partial directories to function correctly.</p>
<p>Once I had the system up and running, I found Firefox performance to be bad. Using the ever-trusty <a title="List Open Files" href="http://en.wikipedia.org/wiki/Lsof" target="_blank">lsof</a>, I found that Firefox uses multiple <a href="http://en.wikipedia.org/wiki/SQLite" target="_blank">sqlite </a>databases to hold stuff like preferences. The solution I decided on was to move my home directory onto a ramdisk. Since I had a small /home partition, I added the following things to my /etc/fstab:</p>
<blockquote><p>UUID=f39t7wj8-v872-4dc9-ik47-nve73hv923nbsw1 /home2           ext4    rw,noatime        0       2<br />
tmpfs /home tmpfs noatime,rw 0 0</p></blockquote>
<p>Your uuid will differ, but the idea is to mount your original /home partition on /home2 instead, and mount /home as a ramdisk. I also added the following to /etc/rc.local:</p>
<blockquote><p>rsync -a /home2/ /home/</p></blockquote>
<p>This syncs the contents of /home2 (which is on the flash) with /home (which is in ram, and discarded at every boot). If I make an important change to my home directory, I log out of my GUI session, open another virtual terminal (by pressing ctrl-alt-F1), log in as root (you will need to set your root password to allow this), and run:</p>
<blockquote><p>rsync -a /home/ /home2/</p></blockquote>
<p>This will sync the changes you made back to the flash card. You should only rarely have to do this. One useful way to save files is to use the free Ubuntu One service which is included with Lucid. That makes it easy to save small files and sync them to the cloud, which ends the worry associated with having your home directory in RAM. Save any files you want to the Ubuntu One directory, and they will be saved offsite.</p>
<p>If you have any issues with doing any of this, feel free to contact me at robwicks@gmail.com. Also, I would greatly appreciate corrections and suggestions. I may experiment with <a href="http://en.wikipedia.org/wiki/Aufs" target="_blank">AUFS</a> in the future. That may be a good alternative to tmpfs alone on some of the filesystems.</p>
<br />Filed under: <a href='http://robwicks.wordpress.com/category/linux/'>linux</a> Tagged: <a href='http://robwicks.wordpress.com/tag/flash/'>flash</a>, <a href='http://robwicks.wordpress.com/tag/linux/'>linux</a>, <a href='http://robwicks.wordpress.com/tag/lucid/'>lucid</a>, <a href='http://robwicks.wordpress.com/tag/thumb-drive/'>thumb drive</a>, <a href='http://robwicks.wordpress.com/tag/tmpfs/'>tmpfs</a>, <a href='http://robwicks.wordpress.com/tag/ubuntu/'>ubuntu</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/robwicks.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/robwicks.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/robwicks.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/robwicks.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/robwicks.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/robwicks.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/robwicks.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/robwicks.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/robwicks.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/robwicks.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/robwicks.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/robwicks.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/robwicks.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/robwicks.wordpress.com/71/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=robwicks.wordpress.com&amp;blog=11037248&amp;post=71&amp;subd=robwicks&amp;ref=&amp;feed=1" width="1" height="1" /><img src="http://feeds.feedburner.com/~r/RobWickssRandomRamblings/~4/SevilRP4pqE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://robwicks.wordpress.com/2010/04/22/ubuntu-thumb-driv/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bbe1b95054377e4b32b421c957748a2c?s=96&amp;d=identicon&amp;r=G" medium="image">
			<media:title type="html">robwicks</media:title>
		</media:content>
	<feedburner:origLink>http://robwicks.wordpress.com/2010/04/22/ubuntu-thumb-driv/</feedburner:origLink></item>
	</channel>
</rss>

