Android BYOD Security based on Trusted Network Connect » History » Version 9
Andreas Steffen, 22.02.2013 15:41
1 | 1 | Andreas Steffen | h1. Android BYOD Security based on Trusted Network Connect |
---|---|---|---|
2 | 1 | Andreas Steffen | |
3 | 3 | Andreas Steffen | An experimental "BYOD version":http://www.strongswan.org/byod/strongswan-byod-1.2.0.apk of the popular "strongSwan Android VPN Client":https://play.google.com/store/apps/details?id=org.strongswan.android allows the collection of integrity measurements on Android 4.x devices. A special Android BYOD IMC written in Java communicates via the TNC IF-M 1.0 Measurement protocol with an Operating System IMV and a Port Scanner IMV. The strongSwan Android VPN Client transports the IF-M messages in IF-TNCCS 2.0 Client/Server protocol batches via the IF-T for Tunneled EAP Methods 1.1 Transport protocol protected by IKEv2 EAP-TTLS. |
4 | 2 | Andreas Steffen | |
5 | 9 | Andreas Steffen | |
6 | 9 | Andreas Steffen | !strongswan-config_small.png!:http://www.strongswan.org/byod/strongswan-config.png |
7 | 9 | Andreas Steffen | |
8 | 9 | Andreas Steffen | The Android VPN client profile *BYOD* specifies the VPN gateway *byod.strongswan.org*, the user authentication is based on *IKEv2 EAP-MD5*, possible user names are *john* or *jane* and the user password is *byod-test*. The *byod.strongswan.org* server certificate is issued by the *strongSwan 2009* certification authority. Therefore the "strongSwan 2009 CA certificate":http://www.strongswan.org/byod/strongswan-cert.crt must be imported into the Android certificate trust store before the first connection can be attempted. |
9 | 2 | Andreas Steffen | |
10 | 2 | Andreas Steffen | h2. Unrestricted Access (TNC recommendation allow) |
11 | 2 | Andreas Steffen | |
12 | 2 | Andreas Steffen | * "Successful connection":http://www.strongswan.org/byod/screenshot-01-connected.png |
13 | 2 | Andreas Steffen | |
14 | 2 | Andreas Steffen | h2. Restricted Access (TNC recommendation isolate) |
15 | 2 | Andreas Steffen | |
16 | 8 | Andreas Steffen | * "Non-Market-Apps Security Setting":http://www.strongswan.org/byod/screenshot-09-non-market-apps-setting.png |
17 | 6 | Andreas Steffen | |
18 | 7 | Andreas Steffen | * "Install Web Server App":http://www.strongswan.org/byod/screenshot-10-kws-webserver.png |
19 | 6 | Andreas Steffen | |
20 | 2 | Andreas Steffen | * "Restricted connection":http://www.strongswan.org/byod/screenshot-02-restricted.png |
21 | 2 | Andreas Steffen | |
22 | 2 | Andreas Steffen | * "Remediation instructions":http://www.strongswan.org/byod/screenshot-03-restricted-remediation.png |
23 | 2 | Andreas Steffen | |
24 | 2 | Andreas Steffen | * "Detailed remediation instructions":http://www.strongswan.org/byod/screenshot-04-restricted-remediation-details.png |
25 | 2 | Andreas Steffen | |
26 | 2 | Andreas Steffen | h2. Blocked Access (TNC recommendation block) |
27 | 2 | Andreas Steffen | |
28 | 5 | Andreas Steffen | * "Start Android Web Server":http://www.strongswan.org/byod/screenshot-08-webserver-active.png |
29 | 4 | Andreas Steffen | |
30 | 2 | Andreas Steffen | * "Failed connection":http://www.strongswan.org/byod/screenshot-05-failure.png |
31 | 2 | Andreas Steffen | |
32 | 2 | Andreas Steffen | * "Remediation instructions":http://www.strongswan.org/byod/screenshot-06-failure-remediation.png |
33 | 2 | Andreas Steffen | |
34 | 2 | Andreas Steffen | |
35 | 2 | Andreas Steffen | * "Detailed remediation instructions":http://www.strongswan.org/byod/screenshot-07-failure-remediation-details.png |