user@astra:~$ sudo apt-get install opensc strongswan libstrongswan-extra-plugins libcharon-extra-plugins libengine-pkcs11-openssl strongswan-nm
user@astra:~$ sudo apt-get install remmina
user@astra:~$ sudo cp ./rootca.crt /usr/local/share/ca-certificates/ user@astra:~$ sudo update-ca-certificates Updating certificates in /etc/ssl/certs... 1 added, 0 removed; done. Running hooks in /etc/ca-certificates/update.d... done.
pkcs11 { load = yes modules { rutoken { load_certs = yes path = /usr/lib/librtpkcs11ecp.so } } }
charon-nm { load-modular = yes plugins { include "/etc/strongswan.d/charon/pkcs11.conf" } tls { key_exchange = ecdhe-ecdsa, ecdhe-rsa, dhe-rsa, rsa cipher = aes256gcm, aes128gcm, chacha20poly1305, aes256, aes128, camellia256, camellia128, null mac = sha1 version_min=1.0 version_max=1.0 } }
user@astra:/home/# sudo lsusb Bus 004 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub Bus 003 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub Bus 001 Device 003: ID 0a89:0030 Aktiv Rutoken ECP Bus 001 Device 002: ID 80ee:0021 VirtualBox USB Tablet Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
user@astra:/home/# ping time.b.users.srcc.msu.ru PING gate-dmz.b.users.srcc.msu.ru (10.89.0.1) 56(84) bytes of data. 64 bytes from gate-dmz.b.users.srcc.msu.ru (10.89.0.1): icmp_seq=1 ttl=63 time=1.74 ms 64 bytes from gate-dmz.b.users.srcc.msu.ru (10.89.0.1): icmp_seq=2 ttl=63 time=1.91 ms 64 bytes from gate-dmz.b.users.srcc.msu.ru (10.89.0.1): icmp_seq=3 ttl=63 time=2.30 ms 64 bytes from gate-dmz.b.users.srcc.msu.ru (10.89.0.1): icmp_seq=4 ttl=63 time=2.30 ms
iMac:~ $ ping time.b.users.srcc.msu.ru ping: cannot resolve time.b.users.srcc.msu.ru: Unknown hostДля исправления указанной ошибки, необходимо создать папку /etc/resolver, поместить в нее файл с именем b.users.srcc.msu.ru с содержимым
domain b.users.srcc.msu.ru search b.users.srcc.msu.ru nameserver 10.89.0.1после чего перезапустить DNS командой sudo killall -HUP mDNSResponder. Затем необходимо повторить ping time.b.users.srcc.msu.ru.
iMac:~ $ sudo mkdir /etc/resolver iMac:~ $ echo -e "domain b.users.srcc.msu.ru\nsearch b.users.srcc.msu.ru\nnameserver 10.89.0.1\n" | sudo tee /etc/resolver/b.users.srcc.msu.ru iMac:~ $ sudo killall -HUP mDNSResponder iMac:~ snussi$ ping time.b.users.srcc.msu.ru PING gate-dmz.b.users.srcc.msu.ru (10.89.0.1): 56 data bytes 64 bytes from 10.89.0.1: icmp_seq=0 ttl=63 time=1.367 ms 64 bytes from 10.89.0.1: icmp_seq=1 ttl=63 time=1.571 ms