1.1 Requirements

1.1.1 Hardware Requirements

  1. 1 or 2 Server Computers (GPCentral and GPRadius) RAM and disk requirements beyond OS needs are minimal (we used 2 Dell Precision 340's with 512MB Ram and 80 Gb disks) (can install system on just one machine, if a seperate radius server is not needed)
  2. Router, for private subnet (we used Cisco 2600)
  3. Switch, for connections to open and private networks (we used Cisco 3550)
    • VLAN capable (capable of trunking)
    • Need 5 ports minimum
  4. Access Point(s) which can Support two SSIDs (we used a Cisco 1100 for a the test network)
  5. Ethernet patch Cables
  6. workstations (wireless laptops) for delegator and guest

1.1.2 Software Requirements

OS

Red Hat Linux 9 or later (any Linux with kernel 2.4.20 or later should work)

Packages

GPCentral

  1. OpenSSH-for administrative access to servers
  2. openssl-0.9.7a or later
  3. DHCP
  4. DNS (Bind v9)
  5. Java 1.4.2-5
  6. Apache v2+
  7. XML-RPCv1.2-b1
  8. OpenSSL 0.9.7
  9. Python 2.2.2
  10. Albatross v1.10
  11. SWIG v1.3.21
  12. ImageMagick
  13. M2Crypto v0.12 (with patches)
  14. netpbm_9.24-10.90.1
  15. Visprint (with patches)
  16. Introcache.py (GP)
  17. TempCA.py (GP)

GPRadius

  1. OpenSSH-for administrative access to servers
  2. openssl-0.9.7a or later
  3. xmlrpc-c-0.9.9
  4. w3c-libwww-5.4.0
  5. sdsi20-0.4.5
  6. Freeradius v1.0.2
    with patches to rlm_eap_tls (GP)
  7. gpradsrc.tar (GP)

Clients

Greenpass depends on 802.1x supplicant SW on the client workstations
Workable versions are:

  1. MacOS 10.3.3 and later
  2. Windows XP SP1 and later
  3. Windows 2000 SP4
  4. Linux with XSupplicant and wireless card drivers installed

1.1.3 Required Certificates

A single cert can be used for multiple roles, depending on the usage and policies of the certificate issuer.
  1. Copy of local CA Root (self signed or from vendor)
  2. SOA certificate (signed by root, with key access to set up)
  3. Server certificates for GPRadius and GPCentral
  4. Applet signing certificate for delegation applet DTool (need key access at setup)
  5. Certificates for users (key access needed to delegate, access network)
  6. Guest Certificate Authority root (an OpenSSL CA works)(key access needed to make certificates)


Return to Main
1 Building Greenpass 2 Running Greenpass



Last edited August 14, 2006
Greenpass Home