288 lines
6.6 KiB
Markdown
288 lines
6.6 KiB
Markdown
# Fedora Kinoite SAW (Secure Air-Gapped Workstation)
|
|
|
|
## Overview
|
|
|
|
This project provides a complete implementation of a **Secure Air-Gapped Workstation (SAW)** using Fedora Kinoite. It implements multiple layers of security including:
|
|
|
|
- **Immutable OS** - Atomic updates with rollback capability
|
|
- **Locked Down DNS** - Only allows connection to VPN gateway
|
|
- **No Sudo Access** - Prevents privilege escalation attacks
|
|
- **Custom CA Trust** - Only packages signed by your Certificate Authority
|
|
- **WireGuard VPN** - Encrypted tunnel for all network traffic
|
|
- **Package Verification** - All packages must be signed and verified
|
|
- **CRL Checking** - Revoked certificates are blocked
|
|
|
|
## Quick Start
|
|
|
|
### Prerequisites
|
|
|
|
- 8GB+ USB drive
|
|
- Fedora Kinoite ISO (base image)
|
|
- CA certificate and private key
|
|
- WireGuard VPN server access
|
|
|
|
### Build ISO
|
|
|
|
```bash
|
|
# Install build tools
|
|
sudo dnf install -y lorax anaconda-tools
|
|
|
|
# Build custom ISO
|
|
cd /home/user/playground/SAW-Kinoite
|
|
sudo bash kickstart/build-iso.sh -i /path/to/Fedora-Kinoite-latest.iso
|
|
```
|
|
|
|
### Install
|
|
|
|
```bash
|
|
# Write ISO to USB
|
|
sudo dd if=output/Fedora-Kinoite-SAW.iso of=/dev/sdX bs=4M status=progress
|
|
|
|
# Boot from USB and install normally
|
|
# Run post-install lockdown
|
|
sudo bash /usr/local/bin/lockdown.sh
|
|
```
|
|
|
|
### Configure VPN
|
|
|
|
```bash
|
|
# Edit WireGuard configuration
|
|
sudo nano /etc/wireguard/wg0.conf
|
|
|
|
# Start VPN
|
|
sudo wg-quick up wg0
|
|
|
|
# Enable auto-start
|
|
sudo systemctl enable wg-quick@wg0
|
|
```
|
|
|
|
## File Structure
|
|
|
|
```
|
|
SAW-Kinoite/
|
|
├── README.md # This file
|
|
├── INSTALLATION_GUIDE.md # Detailed installation instructions
|
|
├── kickstart/
|
|
│ ├── kinoite-saw.ks # Kickstart for custom ISO
|
|
│ └── build-iso.sh # Script to build ISO
|
|
├── post-install/
|
|
│ ├── lockdown.sh # Lockdown script
|
|
│ ├── configure-vpn.sh # WireGuard setup
|
|
│ └── setup-updates.sh # Update approval system
|
|
├── package-verification/
|
|
│ ├── verify-signature.sh # Package verification
|
|
│ ├── verify-crl.sh # CRL verification
|
|
│ └── ca/ # CA configuration
|
|
├── scripts/
|
|
│ ├── security-audit.sh # Security audit script
|
|
│ ├── check-verification.sh # Verification checker
|
|
│ └── daily-crl-update.sh # CRL updater cron job
|
|
└── config/
|
|
└── wireguard/ # WireGuard examples
|
|
```
|
|
|
|
## Security Controls
|
|
|
|
### 1. Sudo Disabled
|
|
- User removed from wheel group
|
|
- Root SSH login disabled
|
|
- PAM configured for MFA
|
|
|
|
### 2. SELinux Enforcing
|
|
- Mandatory access control enabled
|
|
- All security policies enforced
|
|
- Violations logged
|
|
|
|
### 3. Audit Daemon
|
|
- Comprehensive logging enabled
|
|
- Privilege escalation logged
|
|
- Critical file access monitored
|
|
|
|
### 4. Firewall
|
|
- Default deny policy
|
|
- Only WireGuard allowed
|
|
- DNS lockdown configured
|
|
|
|
### 5. DNS Lockdown
|
|
- Only VPN gateway DNS allowed
|
|
- Private DNS blocked
|
|
- All DNS through VPN tunnel
|
|
|
|
### 6. Package Verification
|
|
- GPG signature verification enabled
|
|
- CA key imported
|
|
- CRL checking enabled
|
|
|
|
### 7. Update Approval System
|
|
- Auto-download enabled
|
|
- Approval required for updates
|
|
- Audit trail maintained
|
|
|
|
## Configuration
|
|
|
|
### Custom CA Certificate
|
|
|
|
Place your CA certificate at:
|
|
```
|
|
package-verification/ca/ca.crt
|
|
```
|
|
|
|
### WireGuard Configuration
|
|
|
|
Edit the WireGuard config in:
|
|
```
|
|
/etc/wireguard/wg0.conf
|
|
```
|
|
|
|
### Update Approval
|
|
|
|
Use the approval system:
|
|
```bash
|
|
# Check for updates
|
|
sudo /usr/local/bin/approve-update.sh --check
|
|
|
|
# Approve and apply
|
|
sudo /usr/local/bin/approve-update.sh --approve
|
|
```
|
|
|
|
## Daily Tasks
|
|
|
|
```bash
|
|
# Check for updates
|
|
sudo rpm-ostree status
|
|
|
|
# Check VPN status
|
|
sudo wg show
|
|
|
|
# Check firewall
|
|
sudo firewall-cmd --list-all
|
|
|
|
# View security logs
|
|
sudo ausearch -m avc -ts recent
|
|
```
|
|
|
|
## Weekly Tasks
|
|
|
|
```bash
|
|
# Run security audit
|
|
sudo /usr/local/bin/security-audit.sh
|
|
|
|
# Verify package signatures
|
|
sudo /usr/local/bin/check-verification.sh
|
|
|
|
# Check disk space
|
|
df -h
|
|
```
|
|
|
|
## Monthly Tasks
|
|
|
|
```bash
|
|
# Update CA certificate
|
|
# Update CRL
|
|
# Review audit logs
|
|
# Test rollback capability
|
|
```
|
|
|
|
## Troubleshooting
|
|
|
|
### Package Signature Verification Failed
|
|
|
|
```bash
|
|
# Verify CA key is installed
|
|
ls /etc/pki/rpm-gpg/
|
|
|
|
# Re-import CA key
|
|
sudo rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-custom-ca
|
|
|
|
# Check package signature
|
|
rpm --checksig package.rpm
|
|
```
|
|
|
|
### VPN Not Connecting
|
|
|
|
```bash
|
|
# Check WireGuard config
|
|
cat /etc/wireguard/wg0.conf
|
|
|
|
# Check interface
|
|
sudo wg show
|
|
|
|
# Check firewall
|
|
sudo firewall-cmd --list-services
|
|
```
|
|
|
|
### System Rollback
|
|
|
|
```bash
|
|
# List previous deployments
|
|
sudo rpm-ostree status
|
|
|
|
# Rollback to previous
|
|
sudo rpm-ostree rollback
|
|
sudo reboot
|
|
```
|
|
|
|
## Security Best Practices
|
|
|
|
### Do
|
|
|
|
- ✅ Keep CA key offline and secure
|
|
- ✅ Regularly update CRL
|
|
- ✅ Review audit logs
|
|
- ✅ Test rollback before production
|
|
- ✅ Keep system updated
|
|
- ✅ Verify signatures on all packages
|
|
|
|
### Don't
|
|
|
|
- ❌ Store CA key on the SAW
|
|
- ❌ Disable signature verification
|
|
- ❌ Allow unsigned packages
|
|
- ❌ Disable audit logging
|
|
- ❌ Store passwords in plaintext
|
|
- ❌ Disable SELinux
|
|
|
|
## References
|
|
|
|
### Fedora Documentation
|
|
|
|
- [Fedora Kinoite](https://kinoite.fedoraproject.org/)
|
|
- [Fedora CoreOS Documentation](https://docs.fedoraproject.org/coreos/)
|
|
- [DNF Configuration](https://dnf.readthedocs.io/)
|
|
- [SELinux User Guide](https://docs.fedoraproject.org/en-US/SELinux/)
|
|
- [firewalld](https://firewalld.org/documentation/)
|
|
|
|
### Security References
|
|
|
|
- [NSA Linux Security Hardening Guide](https://media.defense.gov/2022/Aug/29/2003066302/-1/-1/0/CSA_LINX_HARDEN_20220829.PDF)
|
|
- [CIS Fedora Benchmarks](https://www.cisecurity.org/benchmark/ubuntu_linux/)
|
|
- [NIST Security Guides](https://csrc.nist.gov/publications)
|
|
|
|
### Tools Used
|
|
|
|
- [rpm-ostree](https://github.com/ostreedev/rpm-ostree)
|
|
- [Flatpak](https://flatpak.org/)
|
|
- [WireGuard](https://www.wireguard.com/)
|
|
- [firewalld](https://firewalld.org/)
|
|
- [auditd](https://people.redhat.com/sgrubb/audit/)
|
|
- [dnsmasq](http://www.thekelleys.org.uk/dnsmasq/docs.html)
|
|
|
|
## License
|
|
|
|
This implementation is provided as-is for educational and organizational use.
|
|
|
|
**Disclaimer:** This guide provides a starting point. Customize for your specific security requirements and environment. Always test in a safe environment before production deployment.
|
|
|
|
## Support
|
|
|
|
For issues or questions:
|
|
1. Check the troubleshooting section
|
|
2. Review audit logs
|
|
3. Test with minimal configuration
|
|
4. Verify all prerequisites
|
|
|
|
---
|
|
|
|
**Version:** 1.0
|
|
**Date:** 2026-04-02
|
|
**Author:** Fedora Kinoite SAW Implementation |