RHCA筆記 333—1 加解密

來源:互聯網
上載者:User

標籤:openssl   md5   sha   

1.Hashed
    Commonly used to store passwords
    Converts an input string of any length to an output string of fixed length
        One-way:not feasible to get plaintext from hash
        Collision-free:not feasibleto find two strings that hash to the same output
    Algorithms:CRC-32,MD5,SHA-1,SHA-256,etc.
        CRC-32 is not cryptographically secure
    Utilities:sha1sum,md5sum,chsum,openssl dgst
Examples
    To hash file see if it changed
        md5sum file    
            

[[email protected] ~]# vim filethis is a test file[[email protected] ~]# md5sum file79cbbfadcab143d2cc839ce5fce1c576  file[[email protected] ~]# md5sum file79cbbfadcab143d2cc839ce5fce1c576  file[[email protected] ~]# md5sum file79cbbfadcab143d2cc839ce5fce1c576  file

        同一檔案,只要沒有被修改,無論用md5加密多少次,所得字串都一致
        sha1sum file
        openssl dgst -sha1

2.Message Authentication Codes(訊息認證碼)
    MAC is used to maintain the integrity of a network communication,preventing message from tampering
        Attacker needs secret key to forge MAC
    MAC funtion uses a shared secret key to generate MAC
        CBC-MAC:use block cipher to construct
            Encrypt the message in CBC mode and use last block
        HMAC:use keyed cryptographic hash
            HMAC(secret key,message)

3.User Authentication
    Cryptographic hash of account password is stored
        By adding random "salt" to password ,two users with the same password will have different password hashes
        MD5-based hash by default,old modified DES version also availble
    System hashes password given to login
    If passwords match,user is authenticated
    Utilities:password,openssl,openssl passwd -1
    
4.Asymmetric Encryption(非對稱式加密)
    Public key to encrypt,private key to decrypt
        Public means public,private means private
    Partial solution to key distribution problem
        Can give the public key to everybody
    Algorithms:RSA,ElGamal
        RSA is limited in the size of the message(<100 bytes)it can encrypt,much slower than symmetric algorithms
        So,it is common to use RSA to transmit a secret symmetric session key securely,and switch to the faster symmetric secret key
    Utilities:gpg openssl rsautl
    
    Examples
        Generate RSA key
            openssl genrsa 1024 > secret.key
        Extract public key from secret key
            openssl rsa -puboutn-in secret.key > public.key
        echo ‘My secret message .‘ > tomylove.txt
        Encrypt using public key
            openssl rsautl -encrypt -pubin -inkey public.key -in tomylove.txt -out tomylove.encrypt
        Decrypt using secret key
            openssl rsautl -decrypt -inkey secret.key -in tomylove.enc -out tomylove.txt
            使用RSA實現加密的例子
            

[[email protected] ~]# useradd bob[[email protected] ~]# useradd alice[[email protected] ~]# su - bob

                產生bob的私密金鑰,存放到secret.key檔案中
                

[[email protected] ~]$ openssl genrsa 1024 > secret.keyGenerating RSA private key, 1024 bit long modulus...................................++++++.................++++++e is 65537 (0x10001)

                從私密金鑰中提取公開金鑰,存放到public.key檔案中
                

[[email protected] ~]$ openssl rsa -pubout -in secret.key > public.keywriting RSA key

                切換到alice使用者,產生自己的公私密金鑰
                

[[email protected] ~]# su - alice[[email protected] ~]$ openssl genrsa 1024 > secret.keyGenerating RSA private key, 1024 bit long modulus..................................++++++.........................................++++++e is 65537 (0x10001)[[email protected] ~]$ openssl rsa -pubout -in secret.key > public.keywriting RSA key

                現在bob要給alice發送加密訊息:
                    bob用alice的公開金鑰給alice發送加密訊息,alice收到訊息後,用自己的私密金鑰解密即可
                現在alice將自己的公開金鑰發送給bob
                    

[[email protected] ~]$ cp public.key /tmp/alice.pub

                bob現在使用alice的公開金鑰將要發送的檔案tomylove.txt加密
                    

[[email protected] ~]# su - bob[[email protected] ~]$ openssl rsautl -encrypt -pubin -inkey /tmp/alice.pub -in tomylove.txt -out tomylove.enc[[email protected] ~]$ cp tomylove.enc /tmp[[email protected] ~]$ su -[[email protected] ~]# su - alice[[email protected] ~]$ openssl rsautl -decrypt -inkey secret.key -in /tmp/tomylove.enc -out tomylove.txt[[email protected] ~]$ ll tomylove.txt -rw-rw-r--. 1 alice alice 19 Jul 21 23:18 tomylove.txt[[email protected] ~]$ cat tomylove.txt My secret message。

                使用GPG實現加密的例子
                    Generate GPG keys
                        pgp --gen-key(RSA encrypt and sign)
                    Export public key
                        gpg --export -a > pulic.key
                    echo ‘My secret message.‘ > tomylove.txt
                    Encrypt using public key
                        gpg -r keyID -e tomylove.txt(you got tomylove.gpg)
                    Import public key
                        gpg --import public.key
                    Decrypt using secret key
                        gpg -r keyID -o tomylove.txt -d tomylove.gpg
                        
                    
                    
            

       

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.