VPN unter Linux/en: Unterschied zwischen den Versionen

ZIM HilfeWiki - das Wiki
 
(9 dazwischenliegende Versionen von 2 Benutzern werden nicht angezeigt)
Zeile 7: Zeile 7:
 
{{ambox
 
{{ambox
 
|type=notice
 
|type=notice
|text=Linux is only rudimentarily supported by the IMT. Info is addressed to "professionals". Use at your own risk.
+
|text=Linux is only rudimentarily supported by the ZIM. Info is addressed to "professionals". Use at your own risk.
 
}}
 
}}
  
 
<bootstrap_alert color=warning>
 
<bootstrap_alert color=warning>
On 30/03/2023, the certificates for the VPN service were updated. You can use VPN only if you have installed the current configuration file. You do not need to install a new user certificate.
+
&#9888; If you receive an error message such as <code>Decoding PKCS12 failed. Probably wrong password or unsupported/legacy encryption</code> or similar when connecting:<br>
 +
Do not adjust your OpenSSL configuration! Instead, create a new certificate in version 2 (AES-256 container). Details below. Adjusting the OpenSSL configuration can create security risks.
 
</bootstrap_alert>
 
</bootstrap_alert>
  
VPN (Virtual Private Network) is needed if you want to use your computer from outside the university to access services that are only accessible within the university network. VPN guarantees secure access to the university network through other networks (dial-up via other providers, external company or university networks).
+
You need a VPN (Virtual Private Network) if you want to use services from your computer at home that are only accessible within the university network. VPN ensures secure access to the university network from external networks (dial-up via other providers, external company or university networks).
 
<br><br>
 
<br><br>
  
This guide is based on Ubuntu 22.04.2 LTS. Other distributions may work similarly. We cannot provide a guide for every distribution.
+
These instructions are based on Ubuntu 22.04.2 LTS. Other distributions may work in a similar way. We cannot offer instructions for every distribution.
  
== What needs to be done? ==
+
==Simultaneous connections==
 +
<bootstrap_alert color=info>
 +
<span style='font-size:30px;'>&#128712;</span>
 +
<br>
 +
Do you want to connect your laptop and your mobile phone to the VPN in addition to your PC? You can set up VPN connections on multiple devices. However, each person can only establish one connection per VPN at the same time.
 +
</bootstrap_alert>
 +
 
 +
<bootstrap_accordion>
 +
<bootstrap_panel heading="What does that mean?" color="info">
 +
'''Uni-VPN'''
 +
* If you use the Uni-VPN, you can only establish one connection at a time.
 +
* You cannot establish a connection to the Uni-VPN on another device at the same time.
 +
* You must disconnect the existing connection first.
 +
 
 +
'''Group VPN'''
 +
* If you use a group VPN, you cannot establish a second VPN connection to this group VPN on another device at the same time.
 +
* You must disconnect the existing connection first.
 +
 
 +
* However, you can connect to the Uni VPN or another group VPN on another device at the same time.
 +
</bootstrap_panel>
 +
</bootstrap_accordion>
 +
 
 +
== What do I need to do? ==
 
* Download personal network certificate.
 
* Download personal network certificate.
 
* Download configuration file:
 
* Download configuration file:
 
<iframe key="infoboard" width="600" height="330" path="vpn-config/index.php?group=uni&os=lin&redirect_gateway=1" />
 
<iframe key="infoboard" width="600" height="330" path="vpn-config/index.php?group=uni&os=lin&redirect_gateway=1" />
* Store network certificate and configuration file in a folder. Don't change the path later.
+
* Save network certificate and configuration file in a fixed folder.
* Rename the certificate.
+
* Rename network certificate.
* Setup VPN
+
* Set up VPN.
  
 
== Step-by-step instructions ==
 
== Step-by-step instructions ==
=== Create network certificate ===
+
=== Create certificate ===
Open the Serviceportal and login with your Uni-Account.
+
You need a network certificate for the VPN connection. If you already have a certificate for Eduroam, you can use that and skip this step.
 +
<br>
 +
Open the service portal and log in with your university account.
 
* http://sp.upb.de
 
* http://sp.upb.de
 
<br>
 
<br>
  
* Click on '''Benutzerverwaltung''' and on '''Netzwerk-Einstellungen'''.
+
* Go to '''User management''' and then to '''Network settings'''.
 
<br clear=all>
 
<br clear=all>
  
[[Datei:eduroam-win10-1.png]]
+
[[File:Eduroam-unter-android-4.png|links|mini|ohne|350px]]
Click on '''Neues Zertifikat erstellen'''.
+
<br>
 +
* Click on '''"Create new certificate"'''.
 
<br clear=all>
 
<br clear=all>
  
[[Datei:eduroam-win10-2.png|links|mini|ohne|350px]]
+
[[Datei:Netzwerkzertifikat-container-v2.png|links|mini|ohne|350px]]
 
<br>
 
<br>
* Insert an identifier like "Laptop <Manufacturer>".
+
* Give the certificate a unique name (e.g. Laptop VPN)
* Click on '''Neues Zertifikat zusenden'''.
+
* Select '''Version 2''' as the file format.
 +
* Then click on '''"Send new certificate"'''.
 
<br clear=all>
 
<br clear=all>
  
[[Datei:Eduroam-ios-3.png|links|mini|ohne|350px]]
+
[[Datei:Netzwerkzertifikat-download.png|links|mini|ohne|350px]]
 
<br>
 
<br>
* You created a new network certificate.
+
* A new network certificate has been created for you.
* Copy the '''Import Passwort''' or leave the tab open for later.
+
* First copy the '''import password''' to the clipboard.
* Download the network certificate via '''"Netzwerkzertifikat herunterladen"'''.
+
* Now click on '''"Download network certificate"'''.
 
<br clear=all>
 
<br clear=all>
  
=== VPN unter Linux konfigurieren ===
+
=== Configuring VPN under Linux ===
 
Download the configuration file, select the VPN you want to connect to and click on Download.
 
Download the configuration file, select the VPN you want to connect to and click on Download.
 
+
Normally, "Uni-VPN (Standard)" should be the right choice, but if you have problems with the connection, try "Uni-VPN-TCP" again.
Usually "Uni-VPN (Standard)" should work, but if you have problems with the connection, try "Uni-VPN-TCP".
 
 
<iframe key="infoboard" width="600" height="330" path="vpn-config/index.php?group=uni&os=lin&redirect_gateway=1" />
 
<iframe key="infoboard" width="600" height="330" path="vpn-config/index.php?group=uni&os=lin&redirect_gateway=1" />
 
<br clear=all>
 
<br clear=all>
<span style="color:green"> Information:</span> You can click here on '''"Download"'''. This is not a screenshot ;-).
+
<span style="color:green"> Note:</span> You can click on '''"Download"''' here and download your configuration file. This is not a screenshot ;-)
 
<br clear=all>
 
<br clear=all>
  
 
<bootstrap_accordion>
 
<bootstrap_accordion>
<bootstrap_panel heading="Den gesamten Internetverkehr durch den Tunnel leiten?">
+
<bootstrap_panel heading="Route all Internet traffic through the tunnel?">
* Access to online resources may require that you route all network traffic through the tunnel.
+
* Accessing online resources may require that you route all network traffic through the tunnel.
* For access to network drives only, you do not need this option.
+
* You do not need this option for pure access to network drives.
 
</bootstrap_panel>
 
</bootstrap_panel>
 
</bootstrap_accordion>
 
</bootstrap_accordion>
  
 
===Create folder===
 
===Create folder===
* Create a new folder and place the network certificate and the configuration file there.
+
* Create a folder and place the network certificate and configuration file there.
 +
** On distributions that use SELinux (e.g. RedHad, Fedora, CentOS etc.) you need to make sure that the location has the correct labels
 +
** These can be checked with <code>ls -laZ PATH</code> and need a label in the form of <code>unconfined_u:object_r:home_cert_t:s0</code>
 +
** By default the directory <code>~/.cert/</code> should have the correct labels for the network certificate
 +
** Debian/Ubuntu based distributions normally '''do not''' use SELinux and should therefore not be affected by this
 
* Choose the location carefully - you must not move or rename the folder later.
 
* Choose the location carefully - you must not move or rename the folder later.
* Rename the network certificate in <code>Network_Certificate.p12</code>
+
* Rename the network certificate to <code>Network_Certificate.p12</code>
 
 
  
 
[[Datei:Vpn-unter-linux-01.png|links|mini|ohne|350px|Folder for VPN]]
 
[[Datei:Vpn-unter-linux-01.png|links|mini|ohne|350px|Folder for VPN]]
 
<br>
 
<br>
* The contents of the folder should look like this.
+
* This is what the contents of the folder should look like.
 
<br clear=all>
 
<br clear=all>
  
===Configure VPN===
+
===Set up VPN===
 
[[Datei:Vpn-unter-linux-02.png|links|mini|ohne|350px|Network]]
 
[[Datei:Vpn-unter-linux-02.png|links|mini|ohne|350px|Network]]
 
<br>
 
<br>
 
* Click on the '''"Network symbol"'''.
 
* Click on the '''"Network symbol"'''.
* Click on '''"Settings"'''.
+
* Then click on '''"Settings"'''.
 
<br clear=all>
 
<br clear=all>
  
[[Datei:Vpn-unter-linux-03.png|links|mini|ohne|350px|Add VPN]]
+
[[File:Vpn-unter-linux-03.png|left|mini|without|350px|Add VPN]]
 
<br>
 
<br>
* Click in the VPN area on the <code>+</code> to add a connection.
+
* In the VPN area, click on the <code>+</code> to add.
 
<br clear=all>
 
<br clear=all>
  
 
[[Datei:Vpn-unter-linux-04.png|links|mini|ohne|350px|Import from file]]
 
[[Datei:Vpn-unter-linux-04.png|links|mini|ohne|350px|Import from file]]
 
<br>
 
<br>
* Choose '''"Import from file..."'''.
+
* Select '''"Import from file..."'''.
 
<br clear=all>
 
<br clear=all>
  
[[Datei:Vpn-unter-linux-05.png|links|mini|ohne|350px|Config file]]
+
[[Datei:Vpn-unter-linux-05.png|links|mini|ohne|350px|Configuration file]]
 
<br>
 
<br>
* Navigate to the folder that we created for the VPN.
+
* Open the folder we just created.
* Select the '''config file'''.
+
* Select the '''"Configuration file"'''.
* Click on '''"Open"'''.
+
* Then click '''"Open"'''.
 
<br clear=all>
 
<br clear=all>
  
[[Datei:Vpn-unter-linux-06.png|links|mini|ohne|350px|VPN Settings]]
+
[[Datei:Vpn-unter-linux-06.png|links|mini|ohne|350px|VPN settings]]
 
<br>
 
<br>
* The VPN settings have been imported from the config file.
+
* The VPN settings have been imported from the configuration file.
* Insert the '''"Import-Passwort"''' for the network certificate. (1)
+
* Enter the '''"Import password"''' for the network certificate. (1)
* Click on '''"Add"'''. (2)
+
* Then click on '''"Add"'''. (2)
 
<br clear=all>
 
<br clear=all>
  
 
[[Datei:Vpn-unter-linux-07.png|links|mini|ohne|350px|Connect VPN]]
 
[[Datei:Vpn-unter-linux-07.png|links|mini|ohne|350px|Connect VPN]]
 
<br>
 
<br>
* Click on the switch to connect with the VPN.
+
* You can connect to the VPN by clicking on the switch.
 
<br clear=all>
 
<br clear=all>
  
Zeile 119: Zeile 148:
 
[[Datei:Vpn-unter-linux-08.png|links|mini|ohne|350px|Connect VPN]]
 
[[Datei:Vpn-unter-linux-08.png|links|mini|ohne|350px|Connect VPN]]
 
<br>
 
<br>
* You can also connect the VPN via the network menu.
+
* Or establish the connection via the network menu.
 
<br clear=all>
 
<br clear=all>
  
==Disconnect VPN==
+
===Disconnect VPN===
 
[[Datei:Vpn-unter-linux-09.png|links|mini|ohne|350px|Disconnect VPN]]
 
[[Datei:Vpn-unter-linux-09.png|links|mini|ohne|350px|Disconnect VPN]]
 
<br>
 
<br>
* Disconnect the VPN via the network menu.
+
* You can disconnect the VPN connection via the network menu.
 
<br clear=all>
 
<br clear=all>
  
==Check VPN==
+
==Unpack container==
You can check your VPN connection by visiting:
+
If there are problems using the certificate in its container format with the export password provided, it may help to unpack the container into certificate and key.
: [https://go.upb.de/ip https://go.upb.de/ip]
+
<br>
 +
These problems occur, for example, with the old container format under distributions that use OpenSSL 3 or newer. Here you can either unpack the previous container (in order to reference the key and certificate directly) or request a new certificate with the new container format in the service portal.
 +
<br>
 +
 
 +
The OpenSSL version can be checked as follows:
 +
<pre>$ openssl version</pre>
 +
 
 +
The container can be unpacked as follows:
 +
<pre>
 +
$ openssl pkcs12 -in Network_Certificate.p12 -out Network_Certificate_cert.pem -clcerts -nokeys
 +
$ openssl pkcs12 -in Network_Certificate.p12 -out Network_Certificate_key.pem -nocerts -nodes
 +
</pre>
 +
 
 +
The two new files are copied to a safe location in the user directory with the network certificate.
 +
When unpacking the old container format, an additional parameter <code>-legacy</code> is required under OpenSSL 3, otherwise this will be refused.
 +
 
 +
==Edit configuration==
 +
If you do not select the certificates via the GUI, but use the configuration file via the command line, you must ensure that the files are named appropriately for the configuration file. If you have unpacked the container, you must adjust the configuration file accordingly.<br>
 +
 
 +
'''Configuration file without changes'''
 +
<pre>
 +
#### Betriebssystemanpassungen für Linux ####################
  
[[Datei:OpenVPN verbunden - go_ip.png|center|400px|mini|ohne|Beispiel: Bestehende Verbindung ins Uni-Netz.]]
+
pkcs12 Network_Certificate.p12
<br clear=all>
+
resolv-retry 5
 +
auth-nocache
 +
# oder getrennt:
 +
# cert Network_Certificate_cert.pem
 +
# key Network_Certificate_key.pem
 +
</pre>
  
==Advanced==
+
'''If you have unpacked the container in certificate and key:'''
* '''OpenVPN 2.4''' or newer is mandatory.
+
<pre>
* You can setup VPN via the network manager.
+
#### Betriebssystemanpassungen für Linux ####################
* The certificates need to be unpacked first:
 
  
: <code>$ openssl pkcs12 -in Network_Certificate.p12 -out Network_Certificate_OPVPN.crt.pem -clcerts -nokeys </code>
+
# pkcs12 Network_Certificate.p12
: <code>$ openssl pkcs12 -in Network_Certificate.p12 -out Network_Certificate_OPVPN.key.pem -nocerts -nodes </code>
+
resolv-retry 5
 +
auth-nocache
 +
# oder getrennt:
 +
cert Network_Certificate_cert.pem
 +
key Network_Certificate_key.pem
 +
</pre>
  
* The network certificate and the config file need to be stored in a secure area of the user directory.
 
* Under OpenSSL 3.0.2 maybe an additional parameter is necessary: <code>-legacy</code>
 
* It my be necessary (e.g. Arch) to install the "openssl-1.1" package and run the prompts above with "openssl-1.1" instead of "openssl".
 
  
You need to install the required packages via terminal:
+
==Check VPN==
: <code># sudo apt-get install openvpn network-manager-openvpn network-manager-openvpn-gnome</code>
+
You can check the VPN function by calling:
 +
: [https://go.upb.de/ip https://go.upb.de/ip]
 +
Your IP is displayed there and whether you are on the university network.
  
 +
[[Datei:OpenVPN verbunden - go_ip.png|mitte|400px|mini|ohne|Example: Existing connection to the university network.]]
 +
<br clear=all>
  
 
==See also==
 
==See also==
 
* [[Netzwerk]]
 
* [[Netzwerk]]
 
* [[VPN Problembehandlung]]
 
* [[VPN Problembehandlung]]

Aktuelle Version vom 16. Dezember 2024, 14:48 Uhr

Die deutsche Version finden Sie auf der Seite VPN unter Linux

You need a VPN (Virtual Private Network) if you want to use services from your computer at home that are only accessible within the university network. VPN ensures secure access to the university network from external networks (dial-up via other providers, external company or university networks).

These instructions are based on Ubuntu 22.04.2 LTS. Other distributions may work in a similar way. We cannot offer instructions for every distribution.

Simultaneous connections[Bearbeiten | Quelltext bearbeiten]

Uni-VPN

  • If you use the Uni-VPN, you can only establish one connection at a time.
  • You cannot establish a connection to the Uni-VPN on another device at the same time.
  • You must disconnect the existing connection first.

Group VPN

  • If you use a group VPN, you cannot establish a second VPN connection to this group VPN on another device at the same time.
  • You must disconnect the existing connection first.
  • However, you can connect to the Uni VPN or another group VPN on another device at the same time.

What do I need to do?[Bearbeiten | Quelltext bearbeiten]

  • Download personal network certificate.
  • Download configuration file:

  • Save network certificate and configuration file in a fixed folder.
  • Rename network certificate.
  • Set up VPN.

Step-by-step instructions[Bearbeiten | Quelltext bearbeiten]

Create certificate[Bearbeiten | Quelltext bearbeiten]

You need a network certificate for the VPN connection. If you already have a certificate for Eduroam, you can use that and skip this step.
Open the service portal and log in with your university account.


  • Go to User management and then to Network settings.


Eduroam-unter-android-4.png


  • Click on "Create new certificate".


Netzwerkzertifikat-container-v2.png


  • Give the certificate a unique name (e.g. Laptop VPN)
  • Select Version 2 as the file format.
  • Then click on "Send new certificate".


Netzwerkzertifikat-download.png


  • A new network certificate has been created for you.
  • First copy the import password to the clipboard.
  • Now click on "Download network certificate".


Configuring VPN under Linux[Bearbeiten | Quelltext bearbeiten]

Download the configuration file, select the VPN you want to connect to and click on Download. Normally, "Uni-VPN (Standard)" should be the right choice, but if you have problems with the connection, try "Uni-VPN-TCP" again.
Note: You can click on "Download" here and download your configuration file. This is not a screenshot ;-)

  • Accessing online resources may require that you route all network traffic through the tunnel.
  • You do not need this option for pure access to network drives.

Create folder[Bearbeiten | Quelltext bearbeiten]

  • Create a folder and place the network certificate and configuration file there.
    • On distributions that use SELinux (e.g. RedHad, Fedora, CentOS etc.) you need to make sure that the location has the correct labels
    • These can be checked with ls -laZ PATH and need a label in the form of unconfined_u:object_r:home_cert_t:s0
    • By default the directory ~/.cert/ should have the correct labels for the network certificate
    • Debian/Ubuntu based distributions normally do not use SELinux and should therefore not be affected by this
  • Choose the location carefully - you must not move or rename the folder later.
  • Rename the network certificate to Network_Certificate.p12
Folder for VPN


  • This is what the contents of the folder should look like.


Set up VPN[Bearbeiten | Quelltext bearbeiten]

Network


  • Click on the "Network symbol".
  • Then click on "Settings".


Add VPN


  • In the VPN area, click on the + to add.


Import from file


  • Select "Import from file...".


Configuration file


  • Open the folder we just created.
  • Select the "Configuration file".
  • Then click "Open".


VPN settings


  • The VPN settings have been imported from the configuration file.
  • Enter the "Import password" for the network certificate. (1)
  • Then click on "Add". (2)


Connect VPN


  • You can connect to the VPN by clicking on the switch.


Connect VPN[Bearbeiten | Quelltext bearbeiten]

Connect VPN


  • Or establish the connection via the network menu.


Disconnect VPN[Bearbeiten | Quelltext bearbeiten]

Disconnect VPN


  • You can disconnect the VPN connection via the network menu.


Unpack container[Bearbeiten | Quelltext bearbeiten]

If there are problems using the certificate in its container format with the export password provided, it may help to unpack the container into certificate and key.
These problems occur, for example, with the old container format under distributions that use OpenSSL 3 or newer. Here you can either unpack the previous container (in order to reference the key and certificate directly) or request a new certificate with the new container format in the service portal.

The OpenSSL version can be checked as follows:

$ openssl version

The container can be unpacked as follows:

$ openssl pkcs12 -in Network_Certificate.p12 -out Network_Certificate_cert.pem -clcerts -nokeys
$ openssl pkcs12 -in Network_Certificate.p12 -out Network_Certificate_key.pem -nocerts -nodes

The two new files are copied to a safe location in the user directory with the network certificate. When unpacking the old container format, an additional parameter -legacy is required under OpenSSL 3, otherwise this will be refused.

Edit configuration[Bearbeiten | Quelltext bearbeiten]

If you do not select the certificates via the GUI, but use the configuration file via the command line, you must ensure that the files are named appropriately for the configuration file. If you have unpacked the container, you must adjust the configuration file accordingly.

Configuration file without changes

#### Betriebssystemanpassungen für Linux ####################

pkcs12 Network_Certificate.p12
resolv-retry 5
auth-nocache
# oder getrennt:
# cert Network_Certificate_cert.pem
# key Network_Certificate_key.pem

If you have unpacked the container in certificate and key:

#### Betriebssystemanpassungen für Linux ####################

# pkcs12 Network_Certificate.p12
resolv-retry 5
auth-nocache
# oder getrennt:
cert Network_Certificate_cert.pem
key Network_Certificate_key.pem


Check VPN[Bearbeiten | Quelltext bearbeiten]

You can check the VPN function by calling:

https://go.upb.de/ip

Your IP is displayed there and whether you are on the university network.

Example: Existing connection to the university network.


See also[Bearbeiten | Quelltext bearbeiten]


Bei Fragen oder Problemen wenden Sie sich bitte telefonisch oder per E-Mail an uns:

Tel. IT: +49 (5251) 60-5544 Tel. Medien: +49 (5251) 60-2821 E-Mail: zim@uni-paderborn.de

Das Notebook-Café ist die Benutzerberatung des ZIM - Sie finden uns in Raum I0.401

Wir sind zu folgenden Zeiten erreichbar:


Mo Di - Fr
Vor-Ort-Support Geschlossen Über die Feiertage geschlossen
Telefonsupport 08:30 - 13:00 Über die Feiertage geschlossen


Das ZIM:Servicecenter Medien auf H1 hat aktuell zu folgenden Zeiten geöffnet:

Mo Di - Fr
08:00 - 16:00 Über die Feiertage geschlossen


Cookies helfen uns bei der Bereitstellung des ZIM HilfeWikis. Bei der Nutzung vom ZIM HilfeWiki werden die in der Datenschutzerklärung beschriebenen Cookies gespeichert.